Skip to content

Rate limits ​

Public Merchant API routes are limited per API key, not as one shared bucket for every merchant.

Defaults (configurable on the Chuchu API host):

  • MERCHANT_API_RATE_LIMIT — 60
  • MERCHANT_API_RATE_WINDOW_SECONDS — 60

When Redis is available, the limiter is distributed (one bucket per API key).

When Redis is unavailable, the API does not fail open. It uses a stricter in-process limiter keyed by API key + client IP. The fallback is bounded in memory (oldest windows evicted) and uses floor(limit / 4) (minimum 1).

When exceeded, the API returns 429 with:

http
Retry-After: 12

and code MERCHANT_API_RATE_LIMITED.

Human Chuchu UI requests use a separate IP limiter and are not mixed into this bucket.

Public documentation. No login.