If you poll Gorgias heavily, prefer OAuth for the doubled budget, watch the rate-limit headers on every response, and when you get a 429, wait for the Retry-after duration instead of hammering retries. Design sync jobs to stay under 40 requests per 20 seconds if they must use an API key.

Context: Per the Gorgias docs, OAuth apps get 80 requests per 20 seconds and API key apps get 40 requests per 20 seconds. The response headers tell you where you stand, including X-Gorgias-Account-Api-Call-Limit.