Rate limits
Wafeq e-invoicing ASP applies these request limits in both Live and Sandbox. Paths are relative to https://api.wafeq.com/ae/v1. Each listed path has its own allowance, rather than a single combined allowance across the API.
| Operation | Paths | Requests per minute |
|---|---|---|
| Send a document | POST /invoices, /credit-notes, /self-billing/invoices, /self-billing/credit-notes | 60 |
| Validate a document | POST /invoices/validate, /credit-notes/validate, /self-billing/invoices/validate, /self-billing/credit-notes/validate | 120 |
| List documents | GET /invoices, /credit-notes, /self-billing/invoices, /self-billing/credit-notes | 120 |
| Read a document, XML or reporting history | GET /invoices/{invoice_id}, /invoices/{invoice_id}/xml, /invoices/{invoice_id}/reports | 120 |
| Update document metadata | PATCH /invoices/{invoice_id} | 120 |
| Void an invoice | POST /invoices/{invoice_id}/void | 60 |
| Invoice summary report | GET /reports/invoice-summary | 60 |
| OAuth token exchange, refresh or client credentials | POST /oauth/token | 60 |
| OAuth token revocation | POST /oauth/revoke | 60 |
| Portal onboarding verification and submission | POST /onboarding/verify, /onboarding/submit | 20 |
| Portal onboarding progress | POST /onboarding/operation-status | 60 |
How allowances are shared
Requests authenticated with a valid organization API key or OAuth access token are counted per organization, across its keys, tokens and taxpayers. Another key or taxpayer does not create a new allowance for the same path. Live and Sandbox are separate.
Requests without a recognized valid key or access token are counted per client IP. OAuth token and revocation requests normally authenticate with client credentials, so they use the IP-based allowance.
The current counter uses the concrete URL path, including any document ID. Methods with the same path and configured limit share a counter. For example, reading and updating metadata on the same /invoices/{invoice_id} share its 120/minute allowance.
Handle a rate-limit response
Exceeding an allowance returns 429 Too Many Requests. Pause requests for that path and retry with exponential backoff and jitter. Preserve the same idempotency key when retrying a document submission. Rate-limit and Retry-After headers are not enabled by default; clients must not depend on them.
Current enforcement scope
These are fixed-window, application-level limits. Counters currently live in each server process rather than a shared store, so they do not enforce one global quota across all running instances. There is no default application-wide limit for routes without an explicit rule; taxpayer listing and grant management currently have no explicit application-level throttle.
Updated 5 days ago