# Rate limits

Protect the API with per-key limits.

> Public API · Feedif Docs

- **60 requests per minute** per API key
- Response headers: `X-RateLimit-Limit`, `X-RateLimit-Remaining`, `X-RateLimit-Reset`
- Over limit → HTTP `429` with `Retry-After`

CORS is open (`*`) so browser-based tools can call the API with your key. Prefer server-side usage so keys stay private.

---

Source: /docs/api/rate-limits.md
