Skip to content

Rate Limits & Versioning

API requests are limited to 120 requests per minute. Exceeding the limit returns 429 with a Retry-After header indicating how many seconds to wait before retrying.

The limit is generous for the API’s access pattern: scores are calculated once per day, so most integrations need a handful of requests per customer per day. A polling integration that respects the daily calculation cadence will never approach the limit; if you’re building something batch-shaped across many authorized customers, spread requests and honor Retry-After on any 429.

Additional protections (web application firewall, anomaly detection) run at the edge in front of the API. Legitimate integration traffic will not encounter them.

The API is versioned in the URL path; the current version is v1:

https://api.overspace.io/orion/v1

Additive changes are not considered breaking. New response fields, new endpoints, and new optional query parameters may be introduced within v1 at any time. Write clients that ignore unknown fields.

Breaking changes ship as a new version path. Removing or renaming fields, changing types or semantics, or retiring endpoints will only ever happen in a new version (v2), never in place.

When a version is deprecated, Overspace commits to a minimum of 6 months’ notice before it stops being served. Deprecations are announced in the changelog and communicated directly to organizations with active authorizations.