Our Products & Services
Getting Started
First Time Setup
Getting Started With Jobs
Getting Started with Accounts
Getting Started with Inventory
Getting Started with Ticketing
Setting Sonar up for Billing
Baseline Configuration
How To: Using Sonar's Customer Portal
User Specific Resources
Accounts
Account Groups: Overview & Example Use Cases
Account List View: Overview
Account Management View: Overview
Account Overview Customization
Account Statuses: Overview & Example Use Cases
Account Types: Overview & Example Use Cases
Anchor & Linked Serviceable Addresses: Overview and Best Practices
Archiving an Account: Overview
CPUC Fixed Broadband Deployment by Address
Child Accounts: Best Practices & How Tos
Creating a New Account
Direct Messages: Overview
Disconnecting an Account
FCC Broadband Data Collection (BDC) Filings: How Sonar Can Help
FCC Data Exports: General Overview and Usage
Future Serviceable Addresses: Overview
Lead Intake Form Processing
Notes & Tasks: Best Practices & Use Cases
Scheduled Events: Overview & Use Cases
Serviceable Addresses: Overview and Usage
Specify Account ID upon Creation
Using Sonar's FCC Broadband Label Generation Tool
Billing
ACH Batching: Overview
Accounts in Vacation Mode
Avalara: Overview & Setup
Batch Payments & Deposit Slips: Overview
Billing Calculator
Billing Defaults
Billing Settings
Building Packages
Building a Data Service
Canadian ACH tool
Changing Service Pricing in Sonar: Best Practices
Considerations When Using Avalara with Voice Services
Creating Discounts for Services and Packages
Delinquency Billing Best Practices
Delinquency Exclusions: Overview and Use Cases
Dual Data Services: Overview
Email Invoice Batch: Overview
General Ledger Codes: Overview
General Transactions: Best Practices
How Sonar Prorates Billing
How to Take Bank Account Payments
How to: Adding a Service to an Account
Invoice Templates: Overview
Leveraging PayPal as a Payment Method in Sonar
Manual Transactions
Multi-Month Billing & Multi-Month Services
Print to Mail
Printed Invoice Batches: Overview
Services: Overview
Setting Up Payment Methods and Taking Payments
Setting up Bank Account & Credit Card Processors
Taxes Setup
Usage Based Billing Policies: Overview and Usage
Usage Based Billing Policy Free Periods: Overview and Usage
Using Tax Exemptions - How To
Communication
Communications: Call Logs Overview & Best Practices
Communications: Messages Overview
Email Variables & Conditions
Message Categories: Overview & Use Cases
Phone Number Types: Overview and Use Cases
Saved Messages: Overview
Setting up an Outbound Email Domain
Trigger Explanations
Triggered Messages: Setup
Using Outbound SMS
Using the Mass Message Tool
Companies
How to: Setting Up a Company in Sonar
Managing Multiple Companies in Sonar: Best Practices
Rebranding your Sonar Instance
Financial
Contract Templates
Invoice Attachment Use Cases & PDF Examples
Invoice Messages: Overview & Use Cases
Invoices in Sonar: Examples, Creation & Contents
Integrations
Calix Cloud Data Field Mappings
Calix SMx Integration: Overview
CrowdFiber Integration
External Marketing Providers
GPS Tracking Providers: Overview
GoCardless Integration: Overview & Setup
How to Connect Cambium to your Sonar Instance
How to Connect Preseem to your Sonar System
How to: Using Webhooks in Sonar
Integrating with Calix Cloud
RemoteWinBox - Integration with Sonar
The Sonar Field Tech App
Tower Coverage Integration: Overview
VETRO FiberMap V2 Integration: Overview
VETRO FiberMap V3 Integration: Overview
Webhooks in Sonar: Basic PHP Example
iCalendar Integration
Inventory
Inventory List View: Overview
Inventory Model Management: General Overview
Network Inventory: How-to & Usage Guide
Segmentable Inventory: How-to & Usage Guide
Setup of Inventory: Manufacturers, Categories, and Assignees
Tracking and Using Consumable Inventory
Jobs
Applying Task Templates to Jobs
Edit Job Options
Example Jobs & Templates
Geofences: Overview
Job Types: Best Practices
Jobs and Scheduling: Overview
Scheduling How-to: Creating and Booking a Job
Scheduling Week View: Overview
Setting Up Schedules General Overview
Mapping
Misc.
Combining Custom Fields & Task Templates for Information Storage
Custom Fields Overview & Use Cases
Custom Links: Overview
Task Templates Overview & Use Cases
Monitoring
Building Alerting Rotations
Building a Monitoring Template
Poller Troubleshooting
Pollers: General Overview, Deployment Strategy, Build Out & Setup
Networking
Adtran Mosaic Cloud Platform Integration: Overview
Assigning RADIUS Addresses
Assigning an IP Address Using Sonar's IPAM: How to
Automating IP Assignments, Data Rates, and Network Access in Sonar
Building Address Lists
Building RADIUS Groups
Building a Device Mapper
Cable Modem Provisioning
Controlling Customer Speeds with Sonar: General Overview
DHCP Delivery
Data Usage Available Methods
Finding your OIDs
How Sonar Communicates - Egress IPs Explained
IP Assignments & Sonar
IPAM: Basic Setup
IPAM: Overview
LTE Integration
MikroTik as an Inline Device: Integration With Sonar
MikroTik: Controlling Access
MikroTik: Controlling Speeds
MikroTik: Setting Up a Sonar Controlled DHCP Server
Netflow On-Premise Integration: Setup and Overview
Network Dashboard: Overview
Network Sites: Management View Overview
PacketLogic: Integration With Sonar
Pulse, Polling, and PHP
RADIUS: Build-Out & Integration with Sonar
RADIUS: Building Reply Attributes
Setting Up CoA Proxy
Sonar Flow
Sonar IP Addressing
Using Multiple Network Devices in Sonar
Purchase Orders
Release Notes
Reporting
Enhanced Business Intelligence - Tips & Tricks for Advanced Users
How To Enhance Your Reporting With Custom Field Data
Report Licenses
Sonar's Business Intelligence: Overview
Understanding Sonar Reports
Using Sonar DataConnect to Connect BI Applications with Your Sonar Instance
Security
Application Firewall: General Overview and Best Practices
Auth0: Overview
Multi-Factor Authentication: Overview
Password Policy In Depth
Removing a Terminated Employee In Sonar
Role Creation using GraphiQL
User Role Creation & Best Practices
Users: Overview
Sonar Billing
sonarPay
sonarPay Canada Disbursements: Overview
sonarPay Chargebacks & Disputes: Overview
sonarPay Disbursements: Overview
sonarPay Monthly Statement: Overview
sonarPay Overview
sonarPay Reversals, Voids, & Refunds: Overview
sonarPay: Token Migration Process
System
A Deeper Dive into the New Sonar API
API Calls Using Third Party Applications: Personal Access Tokens
Browser Compatibility and Minimum Hardware Requirements for Sonar
Consuming the Sonar API
Controlling Your Landing Page: Personal Preferences
Customizing Your Customer Portal
Date/Time Picker: Overview
Dynamic Time Zones in Sonar
Filtering: Overview
Frequently Used Terms
Getting Your Data into Sonar
GraphQL Rate Limiting Overview
How To Use GraphiQL to Understand the Sonar API
How Your Data is Backed Up
How to Best Use Global Search
Interacting with Files via the API
Introducing the New Sidebar
Main Menu: Overview
Mutations in the Sonar API
Notification Preferences
REST API Wrappers for V1 Compatibility
SMS Notifications
Sonar's Rich Text Editor
System Settings: Overview
The New Sonar API
Troubleshooting the Customer Portal
Upgrading your Ubuntu OS - Customer Portal Upgrades
User Profile: Your Personal User Settings
Ticketing
Advanced Ticketing Features
Canned Replies Examples & Templates
Canned Reply Categories
Exploring Ticket Groups
How Sonar Manages Spam Tickets
How to Integrate Inbound Mailboxes with Slack
Inbound Mailboxes Example Build
Ticket Categories: Overview
Ticketing: Overview
Using Parent Tickets
Voice
API Changes for Voice Billing
Best Practices to Remain CPNI Compliant
Billing Voice Services in Sonar
Deploying Voice Services in Sonar
Working With the Sonar Team & Additional Resources
Sonar's Security Practices & Certifications
Sonar and General Data Protection Regulation (GDPR)
Sonar's Security Strategies
Technical Security Overview
Best Practices for Fast Tracking a Support Request
Feedback Portal / Suggest a Feature
Learning with Sonar: Tools and Resources
New Client Training Overview
Sonar Casts Table of Contents
Submitting Bugs vs. Feature Requests
The Sonar Community Forum
The Sonar Status Page
Third Party Customer Support Referrals
Table of Contents
- All Categories
- System
- GraphQL Rate Limiting Overview
GraphQL Rate Limiting Overview
Updated
by Jennifer Trower
Read Time: 4 mins
GraphQL rate limiting is a control mechanism introduced by Sonar to manage the number of API requests a user can make in a given time frame. This approach supports fair usage, protects backend systems, and ensures a consistent experience for all users. As usage patterns grow in complexity across clients, scalable management of system resources becomes increasingly important.
What Is GraphQL Rate Limiting?
Rate limiting defines the number of API requests a user can make within a specific timeframe. In Sonar’s GraphQL API, each user is allowed up to 400 requests per minute. When this limit is exceeded, additional requests are blocked and a clear error response is returned. The counter resets every 60 seconds, allowing request flow to resume normally once a new interval begins.
{"error": "Request limit of 400/min reached."}
Why Rate Limiting Is Important
Rate limiting plays a key role in maintaining the health and reliability of the Sonar platform. It helps prevent backend systems from becoming overwhelmed by high volumes of traffic, particularly from misconfigured or overly aggressive scripts. By setting clear usage thresholds, it ensures that no single user can disrupt the experience for others, especially in shared environments. These transparent limits guide users toward responsible API usage and support efficient integration practices. Overall, rate limiting is a critical part of Sonar’s broader effort to build a scalable, high-performance platform.
How Limits Were Determined and What to Expect
The current rate limits were established based on an extensive review of actual client usage data. By analyzing real-world traffic patterns, Sonar aimed to define limits that maintain platform stability without disrupting typical user workflows. These limits are part of a phased strategy, with the intent to gradually lower thresholds over time to ensure long-term sustainability, while preserving a positive customer experience.
Upcoming limit reductions will be carefully monitored and tested after regular business hours (starting at 5:00 PM PST). If any issues arise—such as legitimate users hitting limits unexpectedly—Sonar is prepared to reverse changes or apply custom per-instance limits as needed to ensure minimal disruption.
This rate-limiting strategy complements the GraphQL query complexity limits introduced last year. While complexity limits act as a safeguard against unusually demanding queries, they are currently set above realistic usage levels and have not been triggered in production. As such, they are not expected to interfere with standard operations or contribute to throttling alongside the request rate limits.
Adapting to Client Needs
Sonar recognizes that clients interact with the GraphQL API in diverse and evolving ways. A universal rate limit may not serve every use case effectively. To address this, Sonar is evaluating a tiered rate-limiting system that would enable differentiated limits based on user roles, usage patterns, or subscription levels—offering greater flexibility and scalability.
API & UI Rate Limiting Policy
To further enhance system stability, performance, and security, Sonar has implemented a unified Rate limiting policy for both API and UI usage. This ensures consistent and fair access across all interaction channels.
Initial Limit
The Rate limiting policy applies to the total number of requests made by a user, combining activity from both the Sonar web UI and the API. This means that any requests sent while logged into the UI, along with those made via API tokens linked to the same user, are counted together.
Recommendations for API Integrations
If your application integrates with the Sonar API and makes frequent or high-volume requests, it is strongly recommended to create separate user accounts for different types of access. For example, one account can be used for standard UI interactions by staff members, while another is designated specifically for automated API calls by a service user or machine account. This separation helps distribute traffic across individual rate limits, significantly reducing the risk of hitting throttling thresholds due to combined usage under a single account.
Enforcement Details
When a user exceeds the defined rate limit, the system responds with an {"error": "Request limit of 400/min reached."}
. Throttling is enforced on a per-user basis, meaning that all requests made using any tokens associated with the same user are counted collectively toward the limit.
Best Practices to Avoid Throttling
To minimize the risk of throttling and ensure smooth API interactions, it’s important to follow several best practices.
- Implementing exponential backoff when retrying failed requests can prevent repeated overload attempts.
- Distributing API calls evenly throughout each minute, rather than sending bursts of requests, helps maintain a steady request flow.
- Additionally, separating UI logins and API integrations across different user accounts prevents shared usage from unintentionally exceeding rate limits.