[API Update] API Rate Limit Tuning


Hi Creators,

After October 19, we are updating cookie and unauthenticated IP based rate limits for the following services to better reflect real-world usage patterns:

  • badges-api
  • datastores-api
  • game-persistence-api
  • inventory-api
  • thumbnails-api
  • users-api

Open Cloud limits are not impacted. The new limits are data-driven, based on observed request rates.

If you run a tool, extension, or workflow that calls these endpoints, check the tables below and file a bug report if you expect impact.

Who Is impacted

  • Regular users/clients: Minimal to no impact. Limits are set above observed peak usage.
  • Third party integrations, extensions, and workflows: We don’t expect you to hit the new limits, but bursts above normal peak usage could trigger rate limiting.

For each endpoint your tool, workflow, or extension uses:

  • If you expect to be affected or are affected by the rate limit change, please file a bug report.
  • If you don’t expect to be affected and you are still using cookies for automation, please file a feature request/bug report detailing your current use case and what you would like to see supported on Open Cloud.

What To Do If You’re Affected

If you hit rate limits after this change, or expect to:

  1. Review your request volume and add caching where possible.
  2. File a bug report in this forum with your use case and request volume so we can evaluate adjustments.
  3. See if there’s an Open Cloud alternative you can use.

Updated Limits by Service

thumbnails-api

Endpoint Limit Before After Open Cloud Alternative
/v1/assets-thumbnail-3d Per auth cookie, per minute 10,000 100 Get 3D asset thumbnail
/v1/batch Per auth cookie, per minute 10,000 260 None
/v1/bundles/thumbnails Per auth cookie, per minute 10,000 100 None
/v1/developer-products/icons Per auth cookie, per minute 10,000 150 None
/v1/games/{universeId}/thumbnails Per auth cookie, per minute 10,000 100 None
/v1/users/outfit-3d Per auth cookie, per minute 10,000 100 Get 3D outfit thumbnail
/v1/places/gameicons Per auth cookie, per minute 10,000 130 None

badges-api

Endpoint Limit Before After
/v1/users/{userId}/badges Per unauthenticated IP, per minute 1,000 100
/v1/universes/{universeId}/badges/is-authorized-to-reorder Per unauthenticated IP, per minute 1,000 100
/v2/universes/{universeId}/badges Per unauthenticated IP, per minute 1,000 100

inventory-api

Endpoint Limit Before After Open Cloud Alternative
/v1/packages/{packageId}/assets Per auth cookie, per minute 1,000 140 None
/v1/collections/items/{itemType}/{itemTargetId} Per auth cookie, per minute 1,000 100 None
/v1/users/{userId}/items/{itemType}/{itemTargetId}/is-owned Per auth cookie, per minute 10,000 730 List inventory items
/v1/users/{userId}/items/{itemType}/{itemTargetId} Per auth cookie, per second 10,000 220 List inventory items
/v1/users/{userId}/categories Per auth cookie, per minute 10,000 100 None
/v1/users/{userId}/categories/favorites Per auth cookie, per minute 10,000 100 None
/v2/inventory/asset/{assetId} Per auth cookie, per minute 10,000 100 None
/v1/users/{userId:long}/places/inventory Per auth cookie, per minute 10,000 590 None
/v1/users/{userId:long}/places/inventory Per unauthenticated IP, per minute 1,000 280 None

users-api

Endpoint Limit Before After Open Cloud Alternative
/v1/users/ Per auth cookie, per second 1,000 100 Get user (one user per call)
/v1/users/ Per unauthenticated IP, per second 1,000 100 Get user (one user per call)

game-persistence-api

Endpoint Limit Before After Open Cloud Alternative
/v2/persistence/{universeId}/datastores/objects/ (GET) Per auth cookie, per minute 1,000 200 List data store entries
/v2/persistence/{universeId}/datastores/objects/ (POST) Per auth cookie, per minute 1,000 200 Create data store entry

datastores-api

Endpoint Limit Before After Open Cloud Alternative
/datastores/v1/user/universes/{universeId}/standard-datastores Per auth cookie, per minute 1,000 200 List data stores
/datastores/v1/user/{universeId}/standard-datastores Per auth cookie, per minute 1,000 110 List data stores
29 Likes

This topic was automatically opened after 10 minutes.

so who abused the apis for this to happen?

for anyone who wanted a simplified, summed up version of what important changed:

also a bit off topic but can we get a fix to this so third party sites can fix dynamic face tracking finally?

30 Likes

Hey all my games either 0 ccu or average 6 and below are all being flagged for “over limit”, this fr? RN only in datastore manager. How u expect a brand new game that has no earnings yet to pay for more? That’s no profit for a new game

4 Likes

a complete idiot probably using some vibecoded bot making way more requests than necessary by the sounds of it

26 Likes

This is a visual bug and will be fixed soon. You aren’t actually over the limit.

2 Likes

Oh thank you! Can confirm its fixed on my end, was trying to find a bug report on this but couldn’t find it when I first saw this, thought the first thing I do is complain while seeing this announcement, thank you again for letting me know I was worried

2 Likes

i understand why you wanna lower it but some of us (I) have valid use cases

At least replace the cookie based API first

Again, Roblox keeps stepping on Developers foot

1 Like

If you have valid use cases why are you not explaining your use case and why it needs such an absurdly large rate limit in the first place so that they have a better time understanding if it is actually valid and should be considered?

7 Likes

well this sucks, gonna impact my new game a lot

1 Like

I have a Discord bot that checks for Badges and Gamepasses for my game

those are the only concerns and use case that I have

Now I don’t think my bot would hit rate limits BUT I’m still not happy with how Roblox is operating here, they could have provided a more elegant solution and transition

2 Likes

Great, so where’s the Roblox announcement regarding the ban wave that’s affected a large chunk of your platform for transferring Robux (or uploading items)?

1 Like

You already clearly have a third party server, is the elegant solution not just to have your game send updated information about the player’s badges and gamepasses as state changes in-game to your server to store/cache?

Keeping your own cache/mirror of third party data you need immediate/constant access to has practically always been the standard expectation when using an API has it not? Shouldn’t have ever hinged on Roblox keeping such luxuriously high rate limits indefinitely when presumably they were simply that high to help gauge what standard usage looked like and update to match like they have now done.

1 Like

So, is it easier to get rate limited now?

3 Likes

im a bit worried about the huge issues on the site since there’s like high chance of being rate limited with lots of extensions enabled.

How likely are we estimating sites like Towerstats or Rolimons to be affected?

This is absolutely insane. WHY on earth would you nuke API limits so much??? How does one switch to “open cloud” apis for in game things for external tools..

Absolutely aseinine move and I hope you reverse it with such a small window we don’t have time to change anything to prevent the crazy throttle.

8 Likes

Nice! Another update that wasn’t needed :smiley:

6 Likes

??? Unprovoked ??? this is kinda unnecessary…

1 Like


oops