Rate limits

Wafeq e-invoicing ASP applies these request limits in both Live and Sandbox. Paths are relative to https://api.wafeq.com/ae/v1. Each listed path has its own allowance, rather than a single combined allowance across the API.

OperationPathsRequests per minute
Send a documentPOST /invoices, /credit-notes, /self-billing/invoices, /self-billing/credit-notes60
Validate a documentPOST /invoices/validate, /credit-notes/validate, /self-billing/invoices/validate, /self-billing/credit-notes/validate120
List documentsGET /invoices, /credit-notes, /self-billing/invoices, /self-billing/credit-notes120
Read a document, XML or reporting historyGET /invoices/{invoice_id}, /invoices/{invoice_id}/xml, /invoices/{invoice_id}/reports120
Update document metadataPATCH /invoices/{invoice_id}120
Void an invoicePOST /invoices/{invoice_id}/void60
Invoice summary reportGET /reports/invoice-summary60
OAuth token exchange, refresh or client credentialsPOST /oauth/token60
OAuth token revocationPOST /oauth/revoke60
Portal onboarding verification and submissionPOST /onboarding/verify, /onboarding/submit20
Portal onboarding progressPOST /onboarding/operation-status60

How allowances are shared

Requests authenticated with a valid organization API key or OAuth access token are counted per organization, across its keys, tokens and taxpayers. Another key or taxpayer does not create a new allowance for the same path. Live and Sandbox are separate.

Requests without a recognized valid key or access token are counted per client IP. OAuth token and revocation requests normally authenticate with client credentials, so they use the IP-based allowance.

The current counter uses the concrete URL path, including any document ID. Methods with the same path and configured limit share a counter. For example, reading and updating metadata on the same /invoices/{invoice_id} share its 120/minute allowance.

Handle a rate-limit response

Exceeding an allowance returns 429 Too Many Requests. Pause requests for that path and retry with exponential backoff and jitter. Preserve the same idempotency key when retrying a document submission. Rate-limit and Retry-After headers are not enabled by default; clients must not depend on them.

Current enforcement scope

These are fixed-window, application-level limits. Counters currently live in each server process rather than a shared store, so they do not enforce one global quota across all running instances. There is no default application-wide limit for routes without an explicit rule; taxpayer listing and grant management currently have no explicit application-level throttle.


Did this page help you?