# Limits and errors

> Rate limits, daily write limits, idempotency keys and RFC 9457 errors.

Source: https://www.panion.travel/docs/api/limits

- Rate limit: 300 requests per minute per key. Past it: 429 with `Retry-After` and `RateLimit-*` headers.
- Daily write limits per key and UTC day (defaults: 2000 check-ins, 50 payment links, 20 cancels, 20 reschedules). Past a limit: 429 with `Retry-After`. Refused actions do not count.
- Idempotency keys are kept 24 hours.
- Freshness: the manifest reads a mirror of your booking system, refreshed nightly and every two hours for near-term departures.
- Analytics: at most 400 days per request and 2 analytics requests at a time per key. The rollups behind them refresh every five minutes.
- Deprecations: a deprecated endpoint answers with `Deprecation` (RFC 9745) and `Sunset` (RFC 8594) headers and keeps working until the sunset date. The changelog announces it first.

## Idempotency-Key

Every write needs an `Idempotency-Key` header (missing: 400). Use a new UUID per action and reuse it only to retry that action. For 24 hours the same key with the same request replays the first response with `Idempotent-Replayed: true`; the same key with a different request answers 422; while the first request is still running a duplicate answers 409.

```sh
curl -X POST "https://www.panion.travel/api/v1/manifest/<id>/checkin" \
  -H "Authorization: Bearer $PANION_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{"status": "checked_in"}'
```

## Errors

Errors are RFC 9457 problem details (`application/problem+json`) with `type`, `title`, `status`, an optional `detail` and a `request_id`. A booking that is not yours answers 404, never 403.

- 401 `https://www.panion.travel/api/v1/docs#problem-unauthorized`: Missing or invalid API key.
- 403 `https://www.panion.travel/api/v1/docs#problem-forbidden`: This key does not have the scope this endpoint needs.
- 404 `https://www.panion.travel/api/v1/docs#problem-not_found`: Not found.
- 400 `https://www.panion.travel/api/v1/docs#problem-invalid_request`: Invalid request.
- 429 `https://www.panion.travel/api/v1/docs#problem-rate_limited`: Too many requests.
- 400 `https://www.panion.travel/api/v1/docs#problem-idempotency_key_required`: This request needs an Idempotency-Key header.
- 422 `https://www.panion.travel/api/v1/docs#problem-idempotency_key_reused`: This Idempotency-Key was used for a different request.
- 409 `https://www.panion.travel/api/v1/docs#problem-idempotency_in_progress`: A request with this Idempotency-Key is still running.
- 429 `https://www.panion.travel/api/v1/docs#problem-daily_limit`: Daily limit reached for this key.
- 422 `https://www.panion.travel/api/v1/docs#problem-not_allowed`: This action is not possible for this booking.
- 503 `https://www.panion.travel/api/v1/docs#problem-unavailable`: A system this action depends on did not answer.
- 500 `https://www.panion.travel/api/v1/docs#problem-internal`: Something went wrong on our side.
