Rate and Usage Limits
API access rate limits apply at a per-API key basis in unit time. The limit is 300 requests per minute. Also, depending on your plan, you may have usage limits. If you exceed either limit, your request will return an HTTP 429 Too Many Requests status code.Rate Limit Headers
Each API response returns the following set of headers to help you identify your use status:Tools API and MCP
The Tools API (/api/tools/v1) applies a second limit of 70 requests per minute per user for each resource, so awards, opportunities, workspaces, and the other resource families each have their own counter. Exceeding it returns HTTP 429 with the standard Tools API error envelope, code: rate_limited, and a Retry-After header.
Which additional limit applies depends on how you send your key:
Requests sent without
X-API-KEY also count toward a limit of 200 requests per minute per IP address, shared by every caller behind that address, which returns HTTP 503.
MCP connections (/api/mcp) are limited to 70 requests per minute per user when authenticated with a personal or agent API key, and 60 requests per minute per connection when authorized through OAuth. Either limit returns HTTP 429 with a Retry-After header.