Scaling up

From a test probe to production volume — rate limits, batching, retries.

Rate limits

Each Worker enforces two limits per-PoP:

  • PER_PAYER — 60 requests per minute per verified payer address.
  • PER_IP_402 — 120 unpaid 402 responses per minute per source IP.

Plus a zone-level WAF rate limit on /v1/*: 300 requests per minute per IP, action managed_challenge.

A 429 response means you hit a limit; the body’s Retry-After header tells you how many seconds to wait. Implement exponential backoff with jitter; do not retry tight-loop.

Batching

Each call returns up to maxUnits rows. For most endpoints that’s 50–200 per call. Prefer one larger call to many small ones — every call pays a verify+settle round-trip to the facilitator (~150–400 ms), and the pricePerUnit is the same either way.

Retries

x402 settlements are idempotent at the facilitator: the EIP-3009 / Permit2 authorisation contains a nonce, so replaying the same signature does not double-charge. On a transport failure (network, 5xx), it is safe to retry the same signed payload.

On verify failure, build a new signature — the server logs the invalidReason, you can find it in your Bazaar buyer dashboard.

SLA / uptime

There is no SLA on v1. We publish the staging API for development; production traffic should code defensively for 5xx. The /v1/healthz endpoint is unpaid and cached for 60 seconds at the edge.