The Customer Account API now enforces a per-customer rate limit of 3000 requests per minute per store, shared across all apps. This affects all apps that call the Customer Account API, but you typically don't need to make changes because normal buyer traffic stays well under this limit.
What changed
The Customer Account API now limits each customer on a store to 3000 requests per minute. This limit is shared across all apps installed on that store that call the Customer Account API. It applies in addition to the existing cost-based rate limit for the API.
When your app exceeds this per-customer limit, the API returns HTTP 429 Too Many Requests with a THROTTLED error and a Retry-After header. For more details, see the Customer Account API rate limits documentation.
Who's affected
This change affects all apps that call the Customer Account API on any store. The per-customer limit applies regardless of which app makes the requests, since the limit is shared across all apps for a given customer and store.
What you should do
You don't need to take action in most cases, since normal buyer traffic should remain well under this per-customer limit.
If your app uses the Customer Account API, you should make sure its retry logic:
- Detects HTTP
429responses. - Reads the
Retry-Afterheader from the response. - Waits for the duration in
Retry-After, then retries the request.