# Rate limits, pagination, network

## Network and limits

- **Your wallet must answer within 5 seconds** per call (§2.7). Aim for well under 1 second.
- GA doesn't filter your source IP on the Operator API. If you restrict inbound traffic to your wallet, allow GA's outbound addresses: `49.13.169.177` and `46.224.156.1` for the sandbox, `49.13.169.177` for production.
- GA enforces no request rate limit on the Operator API today. Keep catalog polling to once a minute or less and use `updated_since`. GA reserves a `429` with `ERROR_CODE_RATE_LIMITED` for abuse.
- Secrets never go into source control, browser code, tickets, or logs.
