Default limits
Rate-limit responses use HTTP
429, include rate_limit_exceeded, and expose limit, remaining, and reset headers. See Errors and retries.
Limits and budgets are currently managed by Mibyan while self-serve controls are being prepared. If you need higher limits or a budget for a project, contact Mibyan. The Billing page in the console is not available yet.
Budgets
A project can monitor a monthly budget or enforce a hard limit. A hard limit rejects new billable requests after recorded monthly estimated spend reaches the configured amount. The rejected request returns429 with the code budget_exceeded. Unlike a rate limit, retrying does not help until the budget is raised or the period resets.
Security checklist
- Keep keys on the server.
- Use separate test and live credentials.
- Apply least privilege and model or endpoint restrictions.
- Configure an appropriate budget.
- Monitor logs and audit activity.
- Revoke exposed or unused keys immediately.
Policies can differ by project or organization. Read response headers instead of hard-coding the default limits.

