Let’s Encrypt rate limits
Two layers: your plan throttle and the shared Let’s Encrypt provider governor. Plan 429s are yours. Shared capacity returns 202 queued.
Two layers
Customer plan limits (per organization) are independent from Let’s Encrypt account limits (shared across the platform). Hitting a plan throttle returns 429 PLAN_ISSUANCE_RATE_LIMIT. Waiting for Let’s Encrypt capacity returns 202 with status queued and reason provider_capacity.
Official endpoints
Test: https://acme-staging-v02.api.letsencrypt.org/directory. Live: https://acme-v02.api.letsencrypt.org/directory. One Let’s Encrypt provider; the global environment chooses the directory.
Upstream Live limits (configurable)
Current documented Live account new-order limit is 300 / 3 hours (refill 1 / 36s). The platform applies a safety factor (default 80%), so the internal bucket starts at 240 with refill ≈ 1 / 45s. Registered domain: 50 / 7 days globally; platform budget 40. Exact identifier set: 5 / 7 days globally; platform budget 4. Authorization failures: 5 / identifier / hour upstream; platform pauses at 3.
ARI renewals
ACME Renewal Information is the primary renewal scheduler when the directory advertises it. Coordinated ARI renewals are not charged against the new-issuance provider budget. They still pass through the queue for fairness and observability. Fallback: renew when about one third of lifetime remains, or halfway for certificates under ten days.
Retry-After
Provider Retry-After is stored and honored. Backoff escalates roughly 1 minute, 10 minutes, 100 minutes, then 1 day, with jitter.
Related
Let’s Encrypt /docs/integrations/certificate-authorities/lets-encrypt. Environments /docs/environments.