Rate limits and usage
Two separate things cap how much you can call the Stolo API. Rate limits control how fast you can call it, per app. Stolo Tokens are what historical analysis data costs, debited from the account that owns the app. Current-day data is free, so a live poller is bounded by rate limits alone; a historical request has to pass both. Trading calls only have rate limits.
Rate limits
Each app has four limits, one per time window. Every authenticated market data request counts against all four at once (trading calls have their own limit, see trading endpoints):
| Window | Limit |
|---|---|
| Per second | 2 requests |
| Per minute | 30 requests |
| Per hour | 600 requests |
| Per day | 3,000 requests |
The daily limit is the one most scripts run into first. An option chain snapshot every 10 seconds for one underlying uses about 2,250 calls in a session, which leaves room for a few hundred candle and symbol calls.
The windows are fixed windows that reset on a clock, not sliding ones.
Every market data call counts, including calls that then fail validation. /authenticate
doesn't count, and neither do /trade calls.
Rate limit headers
Every response to an authenticated call carries three headers describing whichever window is closest to running out:
| Header | Example | Meaning |
|---|---|---|
X-RateLimit-Limit | 30 | The limit for that window |
X-RateLimit-Remaining | 3 | Requests left in that window |
X-RateLimit-Tier | minute | Which window: second, minute, hour, or day |
Reading these lets you slow down before you hit a 429 instead of after.
When you hit a limit (429)
The request is rejected with 429, a Retry-After header in seconds, and a message that
names the window:
HTTP/1.1 429 Too Many Requests
Retry-After: 38
X-RateLimit-Limit: 30
X-RateLimit-Remaining: 0
X-RateLimit-Tier: minute
{
"status": "error",
"message": "Rate limit exceeded (minute): limit 30",
"response_meta": { "api_version": "v1", "message": "", "elapsed_time": "0.91ms" },
"data": null
}
Wait for Retry-After seconds and try again. A rejected request doesn't count against the
longer windows, so a burst that trips the per-second limit doesn't also eat into your
daily quota.
Staying under the limits
Plan against the daily limit first, then check the shorter windows. A session runs 375 minutes, from 9:15 AM to 3:30 PM.
Here's a setup that fits. You watch 3 underlyings and pull each one's option chain every 30 seconds:
- Per minute: 3 × 2 = 6 requests, under 30.
- Per hour: 360 requests, under 600.
- Per day: 6 × 375 = 2,250 requests, under 3,000. That leaves 750 for
/analysis/symbol/infoin the morning and candles after the close.
Here's one that doesn't. You watch 8 underlyings and pull each chain once a minute:
- Per minute: 8 requests, and per hour: 480 requests. Both fine.
- Per day: 8 × 375 = 3,000 requests. That's the whole daily budget, so the last requests of the day fail, and there's nothing left for candles.
The fixes, in order of how much they help:
- Poll less often. Most setups don't need a fresh chain every minute for every underlying. Every 2 minutes for the 8 underlyings above halves the daily total to 1,500.
- Don't poll candles during the session. They only change after 3:40 PM IST. See candles.
- Poll the chain, not single strikes. One
/analysis/option-chaincall returns LTP, OI, and volume for 41 strikes at once. - Cache reference data.
/analysis/symbol/infoexpiries don't change during a day. - Spread out bursts. The limit is two calls a second, and 30 a minute. In a loop, wait at least 2 seconds between calls.
Trading endpoints
The five /trade endpoints have a separate, fixed limit that
doesn't draw on the four windows above:
| Window | Limit |
|---|---|
| Per second | 10 requests |
| Per minute | 300 requests |
It's counted per app, the headers and the 429 response work exactly as described above
(X-RateLimit-Tier is second or minute), and a burst of order calls never eats into
your option chain budget, or the other way round.
Stolo Tokens
Analysis requests for a past date are paid for in Stolo Tokens from the account that owns
the API app, and the same request is free again for 24 hours. Current-day data,
/authenticate, and the /trade endpoints are free, failed calls are refunded, and calls
rejected by the rate limits above are never charged.
Token charges has the cost of each endpoint, how historical
candles are priced per day, and what happens when your balance runs out.