Effective date: 23 August 2026
1. Purpose
Pincode API is shared infrastructure. This policy is intended to keep the free website and API available for normal users while allowing us to act against traffic that is harmful, unlawful or designed to bypass service controls.
2. Current public rate limit
The current documented limit is 6 API calls per 10 seconds per IP address. A 429 response means the request rate must be reduced.
3. Prohibited behaviour
- Bypassing or attempting to bypass rate limits, blocks or access controls through proxy rotation, multiple IP addresses, botnets, relays or similar methods.
- Request flooding, denial-of-service activity, intentionally excessive concurrency or traffic intended to consume unreasonable resources.
- Security probing or vulnerability exploitation without prior written permission where the activity could affect service confidentiality, integrity or availability.
- Introducing malware, malicious payloads or traffic intended to interfere with servers, networks or other users.
- Using the service for unlawful activity, fraud, harassment, rights infringement or unauthorised collection of personal information.
- Ignoring 429 responses and continuing aggressive automated retries.
- Misrepresenting Pincode API as an official government service or falsely claiming endorsement by India Post or a government department.
4. Automated use
Normal search-engine crawling that respects public crawl controls is not treated as abuse merely because it is automated. High-volume application use should use the API and remain within the documented limits. Automated traffic may be restricted if it degrades service for others.
5. Enforcement
We may throttle, challenge, block or temporarily suspend abusive traffic. The duration and scope of a restriction can depend on the volume, severity, repetition and security risk of the activity. Serious or unlawful activity may be reported to an appropriate service provider or lawful authority where necessary.
6. Report abuse or security concerns
To report abuse or suspicious traffic, email abuse@pincodeapi.in. To report a security vulnerability, email security@pincodeapi.in. Please provide enough detail for us to review the issue without sending unnecessary personal or confidential information.