API reference
Errors and rate limits
The Vyostra AI API reports a failure with a standard HTTP status and a JSON body holding an error code and a message. Each API key may make 120 requests per minute. A request over that limit gets a 429 response with a Retry-After header saying how many seconds to wait before trying again.
By Vinayak Tiwari, Co-Founder & Builder. Published .
What does an error response look like?
Every error has the same shape: an error object with a machine-readable code and a human-readable message. Branch on the code. The wording of a message can change.
{
"error": {
"code": "insufficient_scope",
"message": "This API key does not have the leads:read scope."
}
}Which error codes can the API return?
| Status | Code | What it means | What to do |
|---|---|---|---|
| 400 | invalid_request | A parameter is wrong, for example limit outside 1 to 200. | Fix the request. The message names the parameter. |
| 401 | missing_api_key | No Authorization: Bearer header was sent. | Add the header. |
| 401 | invalid_api_key | The key is unknown or has been revoked. | Check for a truncated copy, or create a new key. |
| 403 | api_access_disabled | The account's plan does not include API access. | Move to Starter, Growth or Agency. |
| 403 | insufficient_scope | The key lacks the scope this endpoint needs. | Create a key with that scope. |
| 404 | not_found | The path or the id does not exist in your account. | Check the id. An id from another account also returns 404. |
| 429 | rate_limited | The key made more than 120 requests in a minute. | Wait for the number of seconds in Retry-After. |
| 500 | internal_error | Something failed on our side. | Retry after a short pause. |
How does the rate limit work?
Each key may make 120 requests per minute. Requests are counted in fixed one-minute windows, and the count belongs to the key, not to your account or your IP address.
A request over the limit is rejected with status 429 and this header:
HTTP/1.1 429 Too Many Requests
Retry-After: 60Retry-After is in seconds. Waiting that long always lands in a fresh window.
How should a client retry?
- On 429, wait for
Retry-Afterseconds and send the same request again. - On 500, retry with a growing pause, for example 2, 4, then 8 seconds, and give up after a few attempts.
- On any other 4xx, do not retry. The request will fail the same way until you change it.
This Node.js helper does all three:
async function vyostraGet(path) {
for (let attempt = 0; attempt < 4; attempt++) {
const response = await fetch(`${process.env.VYOSTRA_API_URL}${path}`, {
headers: { Authorization: `Bearer ${process.env.VYOSTRA_API_KEY}` },
})
if (response.ok) return response.json()
if (response.status === 429) {
const seconds = Number(response.headers.get('Retry-After') ?? 60)
await new Promise((resolve) => setTimeout(resolve, seconds * 1000))
continue
}
if (response.status >= 500) {
await new Promise((resolve) => setTimeout(resolve, 2000 * 2 ** attempt))
continue
}
const { error } = await response.json()
throw new Error(`${response.status} ${error.code}: ${error.message}`)
}
throw new Error(`Gave up on ${path} after 4 attempts`)
}How do you stay under the limit?
Listing leads is the call most likely to be repeated. Ask for limit=200 so a full read takes as few requests as possible, and poll on a schedule measured in minutes, not seconds. Sync leads to your CRM or database has a complete loop.
Common questions
What is the rate limit of the Vyostra AI API?
Each Vyostra AI API key can make 120 requests per minute, counted in fixed one-minute windows. The limit is per key, not per account or per IP address, so two integrations with their own keys do not slow each other down.
Why does a valid-looking API key return 401?
From the Vyostra AI API, a 401 with the code invalid_api_key means the key is not recognised: it was mistyped, cut short when copied, or has been revoked. A 401 with the code missing_api_key means the Authorization header was absent or did not start with the word Bearer.
Should I retry a 500 error from the Vyostra AI API?
Yes, with a pause. A 500 with the code internal_error means the request failed on Vyostra AI servers and was not your fault. All endpoints are read-only, so repeating a request is always safe. Wait a few seconds, double the wait on each attempt, and stop after a handful of tries.