Docs
10

Limits and legal clocks

Request rates, rail caps, retries and legal clocks.

  • In the sandbox

In plain words

Some country systems limit how fast invoices may be sent, and some laws set a deadline after the invoice date. This page lists the limits we count and the legal clocks we watch, so a business can plan the size of a batch and the last day an invoice can be sent. Dates and caps come from official sources and must be checked again before anyone relies on them.

Four things set the pace: the size of a request, how often a client may call the API, each client's cap on sends to a rail, and the legal clock on routes that have one.

Request size

A body over 5 MB (5,000,000 bytes) answers 413, with a problem body (payload-too-large). That covers POST /invoices, POST /invoices/xml, POST /validate and POST /credentials.

Request rate

Each client has a budget for each scope of key. It is counted for the client, not for the key, so more keys do not buy more requests.

ScopeCalls a secondCalls a minute
submit20600
read503,000
admin20600

In addition, the care list may be read 30 times a minute and the care evidence 10 times a minute. Past a limit the answer is 429 with a Retry-After header in seconds. Wait that long and send the same call again. A dry run that finds every validator busy answers 503 (busy) with Retry-After in the same way.

The Peppol lookup of a buyer is limited too: 30 lookups a minute and 300 an hour for each client. An answer already kept costs nothing.

Rail caps

The service counts each client's calls to a rail against the rail's published cap. A client is the client on the invoice. An invoice with no client counts under local. The counters are kept in the database, so a restart does not reset them.

RouteCallCap
PL-KSEFSend an invoice10 a second, 30 a minute, 180 an hour
PL-KSEFRead a status30 a second, 120 a minute, 1,200 an hour
RO-EFACTURAAny call1,000 a minute
DE-XRECHNUNG, PEPPOL, FR-PANone published, none applied

When a client is over a cap, its invoice stays queued and is tried again a second later. Nothing is rejected and nothing shows as an error.

Sources, read on 2 Oct 2026: the KSeF API limits and the ANAF OAuth procedure. KSeF counts each context and IP address pair on its own. ANAF gives 1,000 requests a minute for its API and answers 429 above it, and does not say per what.

Polish sends add up: at 180 an hour, 1,000 invoices for one client take about five and a half hours. Poland's offline24 mode gives until the end of the next business day to send. Batch sessions are planned and not built.

Retries for a rail error

Only a temporary error from a rail is retried. A rejection is not: it goes to the care list.

FailureWait before the next try
1st30 seconds
2nd2 minutes
3rd10 minutes
4th30 minutes
5th1 hour
6thNone. The invoice becomes dead_letter and goes to the care list.

A job that dies in the middle of a send asks the route whether it already holds the invoice before it sends again. Webhook retries follow their own schedule (see webhooks).

Two routes have a deadline from the date on the invoice. The service works it out for each invoice at intake.

RouteDeadlineSource
RO-EFACTURAThe end of the fifth working day after the issue date.OUG 89/2025 and an ANAF notice.
PL-KSEFThe end of the next business day after the issue date, which is the offline24 deadline. The service applies it to every Polish invoice.The VAT Act, art. 106nda, as amended by Dz.U. 2025 poz. 1203.

The other routes have no clock. For an invoice that is still queued, the service records an alert when half of the time from the start of the issue date to the deadline has passed, and again at four fifths.

Warning

Two limits of the clock

  • It counts Monday to Friday. It has no national holiday calendar, so a holiday counts as a working day and the real deadline can fall later than the one the service uses.
  • It counts days in UTC. The authorities count in local time, so the day boundary differs by an hour or two.

Alerts are recorded in the service and not sent (see monitoring and alerts). The deadlines are also shown per invoice as deadline_at, for Romania and Poland, when the invoice carries an issue date (see read an invoice). The two deadlines were last checked against these sources on 27 Sep 2026; they are checked again before the docs are published.

On this page