[metadata]
description: Learn about REST API rate limits, how to avoid exceeding them, and what to do if you do exceed them.
google-site-verification: c1kuD-K2HIVF635lypcsWPoD4kilo5-jA_wBFyT4uMY
og:image: https://docs.github.com/assets/cb-345/images/social-cards/rest.png
og:site_name: GitHub Docs
og:title: Rate limits for the REST API - GitHub Docs
og:type: article
og:url: https://docs-internal.github.com/en/rest/using-the-rest-api/rate-limits-for-the-rest-api
page-document-type: article
path-article: rest/using-the-rest-api/rate-limits-for-the-rest-api
path-language: en
path-product: rest
path-version: free-pro-team@latest
status: 200
twitter:card: summary
twitter:description: Learn about REST API rate limits, how to avoid exceeding them, and what to do if you do exceed them.
twitter:domain: docs-internal.github.com
twitter:image: https://docs.github.com/assets/cb-345/images/social-cards/rest.png
twitter:title: Rate limits for the REST API - GitHub Docs
twitter:url: https://docs-internal.github.com/en/rest/using-the-rest-api/rate-limits-for-the-rest-api
viewport: width=device-width, initial-scale=1

[document-links]
API Insights: /en/rest/orgs/api-insights
API Versions: /en/rest/about-the-rest-api/api-versions
About creating GitHub Apps: /en/apps/creating-github-apps/about-creating-github-apps/about-creating-github-apps
About the REST API: /en/rest/about-the-rest-api/about-the-rest-api
Actions concurrency groups: /en/rest/actions/concurrency-groups
Agent tasks: /en/rest/agent-tasks/agent-tasks
Alerts: /en/rest/dependabot/alerts
Artifact attestations: /en/rest/orgs/attestations
Artifact metadata: /en/rest/orgs/artifact-metadata
Artifacts: /en/rest/actions/artifacts
Ask the GitHub community: https://github.com/orgs/community/discussions
Assignees: /en/rest/issues/assignees
Attestations: /en/rest/repos/attestations
Attestations: /en/rest/users/attestations
Authenticating: /en/rest/authentication/authenticating-to-the-rest-api
Autolinks: /en/rest/repos/autolinks
Best practices for using the REST API: /en/rest/using-the-rest-api/best-practices-for-using-the-rest-api
Best practices: /en/rest/using-the-rest-api/best-practices-for-using-the-rest-api
Billing usage: /en/rest/billing/usage
Blobs: /en/rest/git/blobs
Blocking users: /en/rest/orgs/blocking
Blocking users: /en/rest/users/blocking
Blog: https://github.blog
Branches: /en/rest/branches/branches
Breaking changes: /en/rest/about-the-rest-api/breaking-changes
Budgets: /en/rest/billing/budgets
Building a CI server: /en/rest/guides/building-a-ci-server
CORS and JSONP: /en/rest/using-the-rest-api/using-cors-and-jsonp-to-make-cross-origin-requests
Cache: /en/rest/actions/cache
Check runs: /en/rest/checks/runs
Check suites: /en/rest/checks/suites
Classroom: /en/rest/classroom/classroom
Cloud agent repository management: /en/rest/copilot/copilot-cloud-agent-management
Code quality: /en/rest/code-quality/code-quality
Code scanning: /en/rest/code-scanning/code-scanning
Codes of conduct: /en/rest/codes-of-conduct/codes-of-conduct
Codespaces: /en/rest/codespaces/codespaces
Collaborators: /en/rest/collaborators/collaborators
Collaborators: /en/rest/copilot-spaces/collaborators
Comments: /en/rest/gists/comments
Comments: /en/rest/issues/comments
Commit comments: /en/rest/commits/comments
Commit statuses: /en/rest/commits/statuses
Commits: /en/rest/commits/commits
Commits: /en/rest/git/commits
Community: /en/rest/metrics/community
Comparing GitHub's APIs: /en/rest/about-the-rest-api/comparing-githubs-rest-api-and-graphql-api
Configurations: /en/rest/code-security/configurations
Contact support: https://support.github.com
Contents: /en/rest/repos/contents
Copilot Spaces: /en/rest/copilot-spaces/copilot-spaces
Copilot cloud agent management: /en/rest/copilot/copilot-coding-agent-management
Copilot content exclusion management: /en/rest/copilot/copilot-content-exclusion-management
Copilot usage metrics: /en/rest/copilot/copilot-usage-metrics
Copilot user management: /en/rest/copilot/copilot-user-management
Custom patterns: /en/rest/secret-scanning/custom-patterns
Custom properties: /en/rest/orgs/custom-properties
Custom properties: /en/rest/repos/custom-properties
Delivering deployments: /en/rest/guides/delivering-deployments
Dependency review: /en/rest/dependency-graph/dependency-review
Dependency submission: /en/rest/dependency-graph/dependency-submission
Deploy keys: /en/rest/deploy-keys/deploy-keys
Deployment branch policies: /en/rest/deployments/branch-policies
Deployment statuses: /en/rest/deployments/statuses
Deployments: /en/rest/deployments/deployments
Discover resources for a user: /en/rest/guides/discovering-resources-for-a-user
Draft Project items: /en/rest/projects/drafts
Emails: /en/rest/users/emails
Emojis: /en/rest/emojis/emojis
Encrypt secrets: /en/rest/guides/encrypting-secrets-for-the-rest-api
Endpoints for GitHub App installation tokens: /en/rest/authentication/endpoints-available-for-github-app-installation-access-tokens
Endpoints for GitHub App user tokens: /en/rest/authentication/endpoints-available-for-github-app-user-access-tokens
Endpoints for fine-grained PATs: /en/rest/authentication/endpoints-available-for-fine-grained-personal-access-tokens
Enterprise team members: /en/rest/enterprise-teams/enterprise-team-members
Enterprise team organizations: /en/rest/enterprise-teams/enterprise-team-organizations
Enterprise teams: /en/rest/enterprise-teams/enterprise-teams
Environments: /en/rest/deployments/environments
Events: /en/rest/activity/events
Events: /en/rest/issues/events
Expert services: https://services.github.com
Feeds: /en/rest/activity/feeds
Followers: /en/rest/users/followers
Forks: /en/rest/repos/forks
GPG keys: /en/rest/users/gpg-keys
Get started - Checks: /en/rest/guides/using-the-rest-api-to-interact-with-checks
Get started - Git database: /en/rest/guides/using-the-rest-api-to-interact-with-your-git-database
Getting started: /en/rest/using-the-rest-api/getting-started-with-the-rest-api
Gists: /en/rest/gists/gists
Git SSH keys: /en/rest/users/keys
GitHub Apps: /en/rest/apps/apps
GitHub Docs: /en
GitHub event types: /en/rest/using-the-rest-api/github-event-types
GitHub-hosted runners: /en/rest/actions/hosted-runners
Gitignore: /en/rest/gitignore/gitignore
Global security advisories: /en/rest/security-advisories/global-advisories
Home: /en
Installations: /en/rest/apps/installations
Invitations: /en/rest/collaborators/invitations
Issue dependencies: /en/rest/issues/issue-dependencies
Issue event types: /en/rest/using-the-rest-api/issue-event-types
Issue field values: /en/rest/issues/issue-field-values
Issue fields: /en/rest/orgs/issue-fields
Issue types: /en/rest/orgs/issue-types
Issue types: /en/rest/repos/issue-types
Issues: /en/rest/issues/issues
Keeping API credentials secure: /en/rest/authentication/keeping-your-api-credentials-secure
Labels: /en/rest/issues/labels
Learn how to contribute: /contributing
Libraries: /en/rest/using-the-rest-api/libraries-for-the-rest-api
Licenses: /en/rest/licenses/licenses
Machines: /en/rest/codespaces/machines
Make a contribution: https://github.com/github/docs/blob/main/content/rest/using-the-rest-api/rate-limits-for-the-rest-api.md
Markdown: /en/rest/markdown/markdown
Marketplace: /en/rest/apps/marketplace
Members: /en/rest/orgs/members
Members: /en/rest/teams/members
Meta: /en/rest/meta/meta
Milestones: /en/rest/issues/milestones
Network configurations: /en/rest/orgs/network-configurations
Notifications: /en/rest/activity/notifications
OAuth authorizations: /en/rest/apps/oauth-applications
OIDC: /en/rest/actions/oidc
OpenAPI description: /en/rest/about-the-rest-api/about-the-openapi-description-for-the-rest-api
Organization configurations: /en/rest/private-registries/organization-configurations
Organization roles: /en/rest/orgs/organization-roles
Organization secrets: /en/rest/codespaces/organization-secrets
Organization: /en/rest/interactions/orgs
Organizations: /en/rest/codespaces/organizations
Organizations: /en/rest/migrations/orgs
Organizations: /en/rest/orgs/orgs
Outside collaborators: /en/rest/orgs/outside-collaborators
Packages: /en/rest/packages/packages
Pages: /en/rest/pages/pages
Pagination: /en/rest/using-the-rest-api/using-pagination-in-the-rest-api
Permissions for GitHub Apps: /en/rest/authentication/permissions-required-for-github-apps
Permissions for fine-grained PATs: /en/rest/authentication/permissions-required-for-fine-grained-personal-access-tokens
Permissions: /en/rest/actions/permissions
Personal access tokens: /en/rest/orgs/personal-access-tokens
Pricing: https://github.com/pricing
Privacy policy: /en/site-policy/privacy-policies/github-privacy-statement
Privacy: /en/site-policy/privacy-policies/github-privacy-statement
Project fields: /en/rest/projects/fields
Project items: /en/rest/projects/items
Project views: /en/rest/projects/views
Projects: /en/rest/projects/projects
Protected branches: /en/rest/branches/branch-protection
Protection rules: /en/rest/deployments/protection-rules
Pull requests: /en/rest/pulls/pulls
Push protection: /en/rest/secret-scanning/push-protection
Quickstart: /en/rest/quickstart
REST API endpoints for rate limits: /en/rest/rate-limit/rate-limit
REST API endpoints for rate limits: /en/rest/rate-limit/rate-limit#get-rate-limit-status-for-the-authenticated-user
REST API: /en/rest
Rate limit: /en/rest/rate-limit/rate-limit
Rate limits and query limits for the GraphQL API: /en/graphql/overview/rate-limits-and-query-limits-for-the-graphql-api
Rate limits for the REST API: /en/rest/using-the-rest-api/rate-limits-for-the-rest-api#primary-rate-limit-for-authenticated-users
Rate limits: /en/rest/using-the-rest-api/rate-limits-for-the-rest-api
Reactions: /en/rest/reactions/reactions
References: /en/rest/git/refs
Release assets: /en/rest/releases/assets
Releases: /en/rest/releases/releases
Rendering data as graphs: /en/rest/guides/rendering-data-as-graphs
Repositories: /en/rest/repos/repos
Repository access: /en/rest/dependabot/repository-access
Repository secrets: /en/rest/codespaces/repository-secrets
Repository security advisories: /en/rest/security-advisories/repository-advisories
Repository: /en/rest/interactions/repos
Resources: /en/rest/copilot-spaces/resources
Review comments: /en/rest/pulls/comments
Review requests: /en/rest/pulls/review-requests
Reviews: /en/rest/pulls/reviews
Revocation: /en/rest/credentials/revoke
Rule suites: /en/rest/orgs/rule-suites
Rule suites: /en/rest/repos/rule-suites
Rules: /en/rest/orgs/rules
Rules: /en/rest/repos/rules
SSH signing keys: /en/rest/users/ssh-signing-keys
Script with JavaScript: /en/rest/guides/scripting-with-the-rest-api-and-javascript
Script with Ruby: /en/rest/guides/scripting-with-the-rest-api-and-ruby
Search: /en/rest/search/search
Secret scanning: /en/rest/secret-scanning/secret-scanning
Secrets: /en/rest/actions/secrets
Secrets: /en/rest/agents/secrets
Secrets: /en/rest/dependabot/secrets
Security campaigns: /en/rest/campaigns/campaigns
Security managers: /en/rest/orgs/security-managers
Self-hosted runner groups: /en/rest/actions/self-hosted-runner-groups
Self-hosted runners: /en/rest/actions/self-hosted-runners
Social accounts: /en/rest/users/social-accounts
Software bill of materials (SBOM): /en/rest/dependency-graph/sboms
Source endpoints: /en/rest/migrations/source-imports
Stacked pull requests: /en/rest/pulls/stacks
Starring: /en/rest/activity/starring
Statistics: /en/rest/metrics/statistics
Status: https://www.githubstatus.com/
Sub-issues: /en/rest/issues/sub-issues
Tags: /en/rest/git/tags
Teams: /en/rest/teams/teams
Terms: /en/site-policy/github-terms/github-terms-of-service
Timeline: /en/rest/issues/timeline
Timezones: /en/rest/using-the-rest-api/timezones-and-the-rest-api
Traffic: /en/rest/metrics/traffic
Trees: /en/rest/git/trees
Troubleshooting: /en/rest/using-the-rest-api/troubleshooting-the-rest-api
Use GITHUB_TOKEN for authentication in workflows: /en/actions/tutorials/authenticate-with-github_token
User secrets: /en/rest/codespaces/secrets
User: /en/rest/interactions/user
Users: /en/rest/migrations/users
Users: /en/rest/users/users
Using the REST API: /en/rest/using-the-rest-api
Variables: /en/rest/actions/variables
Variables: /en/rest/agents/variables
Watching: /en/rest/activity/watching
Webhooks: /en/rest/apps/webhooks
Webhooks: /en/rest/orgs/webhooks
Webhooks: /en/rest/repos/webhooks
Workflow jobs: /en/rest/actions/workflow-jobs
Workflow runs: /en/rest/actions/workflow-runs
Workflows: /en/rest/actions/workflows
Working with comments: /en/rest/guides/working-with-comments

[content]
Rate limits for the REST API - GitHub Docs
Skip to main content
GitHub Docs
Version:
Free, Pro, & Team
Search or ask Copilot
Search or ask
Copilot
Select language: current language is English
Search or ask Copilot
Search or ask
Copilot
Open menu
Collapse sidebar
Expand sidebar
Scroll breadcrumbs left
Home
REST API
Using the REST API
Rate limits
Scroll breadcrumbs right
REST API
API Version:
2026-03-10 (latest)
Quickstart
About the REST API
About the REST API
Comparing GitHub's APIs
API Versions
Breaking changes
OpenAPI description
Using the REST API
Getting started
Rate limits
Pagination
Libraries
Best practices
Troubleshooting
Timezones
CORS and JSONP
Issue event types
GitHub event types
Authentication
Authenticating
Keeping API credentials secure
Endpoints for GitHub App installation tokens
Endpoints for GitHub App user tokens
Endpoints for fine-grained PATs
Permissions for GitHub Apps
Permissions for fine-grained PATs
Guides
Script with JavaScript
Script with Ruby
Discover resources for a user
Delivering deployments
Rendering data as graphs
Working with comments
Building a CI server
Get started - Git database
Get started - Checks
Encrypt secrets
Actions
Artifacts
Cache
Actions concurrency groups
GitHub-hosted runners
OIDC
Permissions
Secrets
Self-hosted runner groups
Self-hosted runners
Variables
Workflow jobs
Workflow runs
Workflows
Activity
Events
Feeds
Notifications
Starring
Watching
Agent tasks
Agent tasks
Agents
Secrets
Variables
Apps
GitHub Apps
Installations
Marketplace
OAuth authorizations
Webhooks
Billing
Budgets
Billing usage
Branches
Branches
Protected branches
Campaigns
Security campaigns
Checks
Check runs
Check suites
Classroom
Classroom
Code quality
Code quality
Code scanning
Code scanning
Code security settings
Configurations
Codes of conduct
Codes of conduct
Codespaces
Codespaces
Organizations
Organization secrets
Machines
Repository secrets
User secrets
Collaborators
Collaborators
Invitations
Commits
Commits
Commit comments
Commit statuses
Copilot
Cloud agent repository management
Copilot cloud agent management
Copilot content exclusion management
Copilot usage metrics
Copilot user management
Copilot Spaces
Collaborators
Copilot Spaces
Resources
Credentials
Revocation
Dependabot
Alerts
Repository access
Secrets
Dependency graph
Dependency review
Dependency submission
Software bill of materials (SBOM)
Deploy keys
Deploy keys
Deployments
Deployment branch policies
Deployments
Environments
Protection rules
Deployment statuses
Emojis
Emojis
Enterprise teams
Enterprise team members
Enterprise team organizations
Enterprise teams
Gists
Gists
Comments
Git database
Blobs
Commits
References
Tags
Trees
Gitignore
Gitignore
Interactions
Organization
Repository
User
Issues
Assignees
Comments
Events
Issue dependencies
Issue field values
Issues
Labels
Milestones
Sub-issues
Timeline
Licenses
Licenses
Markdown
Markdown
Meta
Meta
Metrics
Community
Statistics
Traffic
Migrations
Organizations
Source endpoints
Users
Organizations
API Insights
Artifact metadata
Artifact attestations
Blocking users
Custom properties
Issue fields
Issue types
Members
Network configurations
Organization roles
Organizations
Outside collaborators
Personal access tokens
Rule suites
Rules
Security managers
Webhooks
Packages
Packages
Pages
Pages
Private registries
Organization configurations
Projects
Draft Project items
Project fields
Project items
Projects
Project views
Pull requests
Review comments
Pull requests
Review requests
Reviews
Stacked pull requests
Rate limit
Rate limit
Reactions
Reactions
Releases
Releases
Release assets
Repositories
Attestations
Autolinks
Contents
Custom properties
Forks
Issue types
Repositories
Rule suites
Rules
Webhooks
Search
Search
Secret scanning
Custom patterns
Push protection
Secret scanning
Security advisories
Global security advisories
Repository security advisories
Teams
Members
Teams
Users
Attestations
Blocking users
Emails
Followers
GPG keys
Git SSH keys
Social accounts
SSH signing keys
Users
Rate limits for the REST API
Learn about REST API rate limits, how to avoid exceeding them, and what to do if you do exceed them.
Copy as Markdown
In this article
About primary rate limits
About secondary rate limits
Checking the status of your rate limit
Exceeding the rate limit
Staying under the rate limit
Getting a higher rate limit
About primary rate limits
GitHub limits the number of REST API requests that you can make within a specific amount of time. This limit helps prevent abuse and denial-of-service attacks, and ensures that the API remains available for all users.
Some endpoints, like the search endpoints, have more restrictive limits. For more information about these endpoints, see
REST API endpoints for rate limits
. The GraphQL API also has a separate primary rate limit. See
Rate limits and query limits for the GraphQL API
.
In general, you can calculate your primary rate limit for the REST API based on your method of authentication, as described below.
Primary rate limit for unauthenticated users
You can make unauthenticated requests if you are only fetching public data. Unauthenticated requests are associated with the originating IP address, not with the user or application that made the request.
The primary rate limit for unauthenticated requests is 60 requests per hour.
Primary rate limit for authenticated users
You can use a personal access token to make API requests. Additionally, you can authorize a GitHub App or OAuth app, which can then make API requests on your behalf.
All of these requests count towards your personal rate limit of 5,000 requests per hour. Requests made on your behalf by a GitHub App that is owned by a GitHub Enterprise Cloud organization have a higher rate limit of 15,000 requests per hour. Similarly, requests made on your behalf by a OAuth app that is owned or approved by a GitHub Enterprise Cloud organization have a higher rate limit of 15,000 requests per hour if you are a member of the GitHub Enterprise Cloud organization. However, requests made by a higher-limit app reduce the remaining budget available for lower-limit authentication methods. For example, if an app with a 15,000 request limit makes 10,000 requests on your behalf, you will have exhausted the 5,000 request budget for your personal access tokens, even though the app has 5,000 requests remaining.
Primary rate limit for Git LFS access
API requests are required when you upload or download Git LFS content. These count towards a separate rate limiting bucket with a limit of 300 requests per minute for unauthenticated requests and 3,000 requests per minute for authenticated requests.
Git LFS uses a batch API which processes 100 Git LFS objects per API request by default. That means unauthenticated users can download 30,000 Git LFS objects per minute and authenticated users can upload/download 300,000 Git LFS objects per minute.
Primary rate limit for GitHub App installations
GitHub Apps authenticating with an installation access token use the installation's minimum rate limit of 5,000 requests per hour. If the installation is on a GitHub Enterprise Cloud organization, the installation has a rate limit of 15,000 requests per hour.
For installations that are not on a GitHub Enterprise Cloud organization, the rate limit for the installation will scale with the number of users and repositories. Installations that have more than 20 repositories receive another 50 requests per hour for each repository. Installations that are on an organization that have more than 20 users receive another 50 requests per hour for each user. The rate limit cannot increase beyond 12,500 requests per hour.
Primary rate limits for GitHub App user access tokens (as opposed to installation access tokens) are dictated by the primary rate limits for the authenticated user. This rate limit is combined with any requests that another GitHub App or OAuth app makes on that user's behalf and any requests that the user makes with a personal access token. For more information, see
Rate limits for the REST API
.
Primary rate limit for OAuth apps
Primary rate limits for OAuth access tokens generated by a OAuth app are dictated by the primary rate limits for authenticated users. This rate limit is combined with any requests that another GitHub App or OAuth app makes on that user's behalf and any requests that the user makes with a personal access token. See
Primary rate limit for authenticated users
.
OAuth apps can also use their client ID and client secret to fetch public data. For example:
curl -u YOUR_CLIENT_ID:YOUR_CLIENT_SECRET -I https://api.github.com/meta
For these requests, the rate limit is 5,000 requests per hour per OAuth app. If the app is owned by a GitHub Enterprise Cloud organization, the rate limit is 15,000 requests per hour.
Note
Never include your app's client secret in client-side code or in code that runs on a user device. The client secret can be used to generate OAuth access tokens for users who have authorized your app, so you should always keep the client secret secure.
Primary rate limit for
GITHUB_TOKEN
in GitHub Actions
You can use the built-in
GITHUB_TOKEN
to authenticate requests in GitHub Actions workflows. See
Use GITHUB_TOKEN for authentication in workflows
.
The rate limit for
GITHUB_TOKEN
is 1,000 requests per hour per repository. For requests to resources that belong to a GitHub Enterprise Cloud account, the limit is 15,000 requests per hour per repository.
About secondary rate limits
In addition to primary rate limits, GitHub enforces secondary rate limits in order to prevent abuse and keep the API available for all users.
You may encounter a secondary rate limit if you:
Make too many concurrent requests.
No more than 100 concurrent requests are allowed. This limit is shared across the REST API and GraphQL API.
Make too many requests to a single endpoint per minute.
No more than 900 points per minute are allowed for REST API endpoints, and no more than 2,000 points per minute are allowed for the GraphQL API endpoint. For more information about points, see
Calculating points for the secondary rate limit
.
Make too many requests per minute.
No more than 90 seconds of CPU time per 60 seconds of real time is allowed. No more than 60 seconds of this CPU time may be for the GraphQL API. You can roughly estimate the CPU time by measuring the total response time for your API requests.
Make too many requests that consume excessive compute resources in a short period of time.
Create too much content on GitHub in a short amount of time.
In general, no more than 80 content-generating requests per minute and no more than 500 content-generating requests per hour are allowed. Some endpoints have lower content creation limits. Content creation limits include actions taken on the GitHub web interface as well as via the REST API and GraphQL API.
Make too many OAuth access token requests in a short period of time.
No more than 2,000 OAuth access token requests per hour are allowed for GitHub Apps and OAuth apps.
These secondary rate limits are subject to change without notice. You may also encounter a secondary rate limit for undisclosed reasons.
Calculating points for the secondary rate limit
Some secondary rate limits are determined by the point values of requests. For GraphQL requests, these point values are separate from the point value calculations for the primary rate limit.
Request
Points
GraphQL requests without mutations
1
GraphQL requests with mutations
5
Most REST API
GET
,
HEAD
, and
OPTIONS
requests
1
Most REST API
POST
,
PATCH
,
PUT
, or
DELETE
requests
5
Some REST API endpoints have a different point cost that is not shared publicly.
Checking the status of your rate limit
You can use the headers that are sent with each response to determine the current status of your primary rate limit.
Header name
Description
x-ratelimit-limit
The maximum number of requests that you can make per hour
x-ratelimit-remaining
The number of requests remaining in the current rate limit window
x-ratelimit-used
The number of requests you have made in the current rate limit window
x-ratelimit-reset
The time at which the current rate limit window resets, in UTC epoch seconds
x-ratelimit-resource
The rate limit resource that the request counted against. For more information about the different resources, see
REST API endpoints for rate limits
.
You can also call the
GET /rate_limit
endpoint to check your rate limit. Calling this endpoint does not count against your primary rate limit, but it can count against your secondary rate limit. See
REST API endpoints for rate limits
. When possible, you should use the rate limit response headers instead of calling the API to check your rate limit.
There is not a way to check the status of your secondary rate limit.
Exceeding the rate limit
If you exceed your primary rate limit, you will receive a
403
or
429
response, and the
x-ratelimit-remaining
header will be
0
. You should not retry your request until after the time specified by the
x-ratelimit-reset
header.
If you exceed a secondary rate limit, you will receive a
403
or
429
response and an error message that indicates that you exceeded a secondary rate limit. If the
retry-after
response header is present, you should not retry your request until after that many seconds has elapsed. If the
x-ratelimit-remaining
header is
0
, you should not retry your request until after the time, in UTC epoch seconds, specified by the
x-ratelimit-reset
header. Otherwise, wait for at least one minute before retrying. If your request continues to fail due to a secondary rate limit, wait for an exponentially increasing amount of time between retries, and throw an error after a specific number of retries.
Continuing to make requests while you are rate limited may result in the banning of your integration.
Staying under the rate limit
You should follow best practices to help you stay under the rate limits. See
Best practices for using the REST API
.
Getting a higher rate limit
If you want a higher primary rate limit, consider making authenticated requests instead of unauthenticated requests. Authenticated requests have a significantly higher rate limit than unauthenticated requests.
If you are using a personal access token for automation in your organization, consider whether a GitHub App will work instead. The rate limit for GitHub Apps using an installation access token scales with the number of repositories and number of organization users. See
About creating GitHub Apps
.
If you are using GitHub Apps or OAuth apps, consider upgrading to GitHub Enterprise Cloud. GitHub Apps or OAuth apps have higher rate limits for organizations that use GitHub Enterprise Cloud.
Help and support
Did you find what you needed?
Yes
No
Privacy policy
Help us make these docs great!
All GitHub docs are open source. See something that's wrong or unclear? Submit a pull request.
Make a contribution
Learn how to contribute
Still need help?
Ask the GitHub community
Contact support
Legal
©
2026
GitHub, Inc.
Terms
Privacy
Status
Pricing
Expert services
Blog
