Introducing rate limiting on the Public API

To ensure the ongoing stability and reliability of the First AML Public API for all of our integration partners, we will be introducing rate limiting.

What is changing

The API will enforce a limit of 300 requests per 5 minute sliding window. Requests made beyond this limit will receive a 429 Too Many Requests response and should be retried once the window allows.

When this takes effect

Environment Date
Sandbox August 17th 2026
Production August 31st 2026

We recommend testing your integration against the Sandbox environment once the limit is in place there to confirm your client handles rate limiting gracefully ahead of the Production rollout.

Who is affected

We expect the vast majority of integrations to operate well within this limit and to be unaffected by this change. We are proactively reaching out to any customers we believe are likely to be impacted.

For more detail on rate limiting and other expectations when using the API, see our Using the API documentation.


Getting Started
Authentication
Domain Concepts
API Features
Zapier
Embedded EIV
Help