Rate limits
Two limits apply, and they protect different things.
Per visitor
Questions from a single visitor are limited by address, at 20 per minute. This bounds one person — a stuck script, a page in a reload loop, someone holding the send key down.
Per account
Widget traffic is also limited across your whole account, at 60 questions per minute by default. This bounds your account as a whole rather than any single visitor, which the per-visitor limit cannot do: a hundred visitors each within their own limit still add up.
If your traffic legitimately needs a higher ceiling, tell us and we will raise it. The default is chosen for a normal storefront, not for a sale day.
What a visitor sees
A visitor who hits a limit is told to try again in a few moments. Their conversation is not lost and they do not have to start again.
How the account limit behaves under failure
The account-level limit is enforced using a separate component, and if that component is unavailable the limit allows the request through rather than blocking it. A rate limiter that cannot reach its counter would otherwise take your support widget offline for everyone, which is a worse outcome than briefly not enforcing a ceiling.
The per-visitor limit does not depend on it.
Direct API calls
Calls made with an API key are not subject to the per-account widget limit, because that limit exists to bound a widget on a public page. If you need a sustained high volume through the API, talk to us so we can plan for it rather than discovering it.
What is not rate limited
Loading the widget script and fetching your configuration are cached and do not count against these limits. Nor does a handoff request, which has its own separate limit per email address per day — see Limits and edge cases in handoff.