Skip to main content
What we can verify about the Public API’s operating limits — from live responses and source — and what isn’t published.

Rate limits

No rate-limit headers (RateLimit-*, X-RateLimit-*, Retry-After) appear on live responses, and no throttle middleware exists in the service source. If you plan high-volume polling, agree a budget with Bluprynt when you request your key — don’t assume the absence of a 429 means unlimited.

Caching

Versioning and deprecation

  • Routes are unversioned today except /api/v1/badges/* and /kyi/v1/*, which carry a v1 segment. New route families land under their own versioned prefix.
  • The served OpenAPI document reports the service version (1.0.0 at integrations.bluprynt.com/openapi.json).
  • Every /assets response carries Deprecation: true (RFC 9745). A planned change to the asset↔deployment model is signalled ahead of time; no removal date is committed yet. When one exists it will also arrive as Sunset (RFC 8594) and a Link: rel="deprecation" header pointing at the migration notice — watch for those two headers to know the timeline is live.
Observed response headers on /assets/*

Spec access

The interactive reference at integrations.bluprynt.com serves the live spec at /openapi.json and /openapi.yaml. Pin your client to it — it’s generated from the same code that answers requests.