Limits & Scopes
Rate limits, scopes, and consent grants in detail.
Rate limits
| Tier | Requests / day per key |
|---|---|
| Free | 100 |
| Builder | 5,000 |
| Enterprise | Custom — contact us |
Limits apply per API key, not per account. A 429 response includes a Retry-After header.
Scopes
Each API key carries a default scope set. Scopes determine what data categories the key can access:
profile.read/profile.writebiomarkers.readwearables.read/wearables.writelabs.read/labs.write/labs.purchasehealth-profile.read/health-profile.writeknowledge.read
Generate keys with the minimum scope needed for the agent. Wider isn't better.
Consent grants
Beyond scopes, individual consent grants can be added or revoked per tool. A key with labs.write can be denied purchaseLabTest specifically without losing other lab capabilities.
Changing limits
- Upgrade tier from the Console
- For enterprise volumes, talk to sales
Best practices
- One key per agent / environment — easier to rotate and revoke
- Read-only keys for analytics / dashboards
- Write keys only on the surfaces that need them
- Rotate keys every 90 days even when not compromised

