# Limiting response size

**URL:** <https://discuss.jsonapi.org/t/limiting-response-size/2898>\
**Category:** Uncategorized\
**Created:** [August 12, 2024, 9:00am UTC](https://discuss.jsonapi.org/t/limiting-response-size/2898 "2024-08-12T09:00:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexvoedi](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@alexvoedi](https://discuss.jsonapi.org/u/alexvoedi)\
**Post date:** [August 12, 2024, 9:00am UTC](https://discuss.jsonapi.org/t/limiting-response-size/2898/1 "2024-08-12T09:00:36Z")

</div>

The API I provide does have a rate limit, but this can be more or less circumvented by simply sending a very large request with a accordingly large response. Such requests can be blocked in principle, but I am interested in whether there is a recommendation for this in the context of JSON:API.

Are there any guidelines or recommendations regarding the maximum size of API responses? Or is this a topic that should be considered completely independently of JSON:API?

---

<div class="post-metadata">

**Author:** ![Bednic](https://avatars.discourse-cdn.com/v4/letter/b/cdc98d/32.png) [@Bednic](https://discuss.jsonapi.org/u/Bednic)\
**Post date:** [August 12, 2024, 12:26pm UTC](https://discuss.jsonapi.org/t/limiting-response-size/2898/2 "2024-08-12T12:26:59Z")

</div>

I believe this is architectural problem. Specification does not contains any limitation for size of data and even cannot dict any restriction. Limitation must be defined via API Contract and it depends on data structure and infrastructure capabilities.
