Punchh Rate Limits
PAR Punchh publishes rate-limiting behaviour in prose in its API Security Guidelines, not as per-endpoint quota tables and not as response headers. The numbers below are the ones PAR actually states. Two things are published and concrete — the authentication lockout thresholds partners are told to implement and that Punchh itself enforces, and the outbound webhook retry ladder. Two things are published but unquantified — the existence of separate direct-access and partner (indirect-access) endpoint tiers with different thresholds, where the partner tier is explicitly "a much higher threshold" gated behind IP allowlisting. Per-key request quotas are shared during partner certification and are not public.
Punchh Rate Limits is the machine-readable rate-limit profile for Punchh on the APIs.io network, conforming to the API Commons Rate Limits specification.
It captures 4 rate-limit definitions.
The profile also includes 3 backoff/retry policies defined and response codes documented for throttled and timeout.
Tagged areas include Rate Limiting, Loyalty, and Restaurant.