Appearance
Rate limits
Public Merchant API routes are limited per API key, not as one shared bucket for every merchant.
Defaults (configurable on the Chuchu API host):
MERCHANT_API_RATE_LIMIT—60MERCHANT_API_RATE_WINDOW_SECONDS—60
When Redis is available, the limiter is distributed (one bucket per API key).
When Redis is unavailable, the API does not fail open. It uses a stricter in-process limiter keyed by API key + client IP. The fallback is bounded in memory (oldest windows evicted) and uses floor(limit / 4) (minimum 1).
When exceeded, the API returns 429 with:
http
Retry-After: 12and code MERCHANT_API_RATE_LIMITED.
Human Chuchu UI requests use a separate IP limiter and are not mixed into this bucket.