API reference

Errors and rate limits

The Vyostra AI API reports a failure with a standard HTTP status and a JSON body holding an error code and a message. Each API key may make 120 requests per minute. A request over that limit gets a 429 response with a Retry-After header saying how many seconds to wait before trying again.

By Vinayak Tiwari, Co-Founder & Builder. Published .

What does an error response look like?

Every error has the same shape: an error object with a machine-readable code and a human-readable message. Branch on the code. The wording of a message can change.

JSON
{
  "error": {
    "code": "insufficient_scope",
    "message": "This API key does not have the leads:read scope."
  }
}

Which error codes can the API return?

StatusCodeWhat it meansWhat to do
400invalid_requestA parameter is wrong, for example limit outside 1 to 200.Fix the request. The message names the parameter.
401missing_api_keyNo Authorization: Bearer header was sent.Add the header.
401invalid_api_keyThe key is unknown or has been revoked.Check for a truncated copy, or create a new key.
403api_access_disabledThe account's plan does not include API access.Move to Starter, Growth or Agency.
403insufficient_scopeThe key lacks the scope this endpoint needs.Create a key with that scope.
404not_foundThe path or the id does not exist in your account.Check the id. An id from another account also returns 404.
429rate_limitedThe key made more than 120 requests in a minute.Wait for the number of seconds in Retry-After.
500internal_errorSomething failed on our side.Retry after a short pause.

How does the rate limit work?

Each key may make 120 requests per minute. Requests are counted in fixed one-minute windows, and the count belongs to the key, not to your account or your IP address.

A request over the limit is rejected with status 429 and this header:

HTTP
HTTP/1.1 429 Too Many Requests
Retry-After: 60

Retry-After is in seconds. Waiting that long always lands in a fresh window.

How should a client retry?

  • On 429, wait for Retry-After seconds and send the same request again.
  • On 500, retry with a growing pause, for example 2, 4, then 8 seconds, and give up after a few attempts.
  • On any other 4xx, do not retry. The request will fail the same way until you change it.

This Node.js helper does all three:

JavaScript
async function vyostraGet(path) {
  for (let attempt = 0; attempt < 4; attempt++) {
    const response = await fetch(`${process.env.VYOSTRA_API_URL}${path}`, {
      headers: { Authorization: `Bearer ${process.env.VYOSTRA_API_KEY}` },
    })

    if (response.ok) return response.json()

    if (response.status === 429) {
      const seconds = Number(response.headers.get('Retry-After') ?? 60)
      await new Promise((resolve) => setTimeout(resolve, seconds * 1000))
      continue
    }

    if (response.status >= 500) {
      await new Promise((resolve) => setTimeout(resolve, 2000 * 2 ** attempt))
      continue
    }

    const { error } = await response.json()
    throw new Error(`${response.status} ${error.code}: ${error.message}`)
  }

  throw new Error(`Gave up on ${path} after 4 attempts`)
}

How do you stay under the limit?

Listing leads is the call most likely to be repeated. Ask for limit=200 so a full read takes as few requests as possible, and poll on a schedule measured in minutes, not seconds. Sync leads to your CRM or database has a complete loop.

Common questions

What is the rate limit of the Vyostra AI API?

Each Vyostra AI API key can make 120 requests per minute, counted in fixed one-minute windows. The limit is per key, not per account or per IP address, so two integrations with their own keys do not slow each other down.

Why does a valid-looking API key return 401?

From the Vyostra AI API, a 401 with the code invalid_api_key means the key is not recognised: it was mistyped, cut short when copied, or has been revoked. A 401 with the code missing_api_key means the Authorization header was absent or did not start with the word Bearer.

Should I retry a 500 error from the Vyostra AI API?

Yes, with a pause. A 500 with the code internal_error means the request failed on Vyostra AI servers and was not your fault. All endpoints are read-only, so repeating a request is always safe. Wait a few seconds, double the wait on each attempt, and stop after a handful of tries.