Skip to main content

Each integration client can send 600 requests a minute, across all its keys. Billing an encounter also counts against the practice: 30 a minute across all its clients, and past that the practice's billing waits five minutes. Every answer says where you are:

HeaderMeaning
X-RateLimit-LimitRequests allowed in the current window
X-RateLimit-RemainingRequests left in it
X-RateLimit-ResetWhen the window resets, in seconds since the Unix epoch

Over the limit, the answer is a 429 with a Retry-After header in seconds. Wait that long, then carry on. The client is held for a minute, so retrying sooner only gets more 429s.

Keep well under the limit

  • Sync changes with webhooks and a _lastUpdated search rather than reading every record on a timer.
  • Reuse what you've read. A patient's id doesn't change, so look it up by your patient number once and keep it.
  • Back off on 429 and 5xx with a growing delay, and retry a create with the same Idempotency-Key.

Separately, one address that sends 30 requests with a bad key in 10 minutes is refused for 10 minutes. A misconfigured deploy that keeps retrying with a revoked key hits this first.