1. Know what triggers it
Each key is compared with its own last 14 days, never with anyone else's. The notice is sent when a key's requests so far today (UTC) reach ten times its daily average and at least 2,000. A key needs at least 7 days of use before it can trigger one, so a new key never does.
2. Check whether it was you
The notice names the key and its prefix, today's number and the average it was compared with. Open API keys in your account settings to see that key's usage by day and how it splits between the REST API and the MCP server. A new script, a backfill or a bug in your own retry loop are the usual reasons.
3. Revoke it if it was not
If you do not recognize the traffic, revoke the key from API keys and create a new one for the integrations that need it. Revoking takes effect on the next request.
4. How often you will hear
At most once a day per key. It goes wherever your account sends alerts: your account email by default, and Slack, PagerDuty or webhooks if you have set them up.
Go deeper
The full reference lives in the docs: API documentation. Error codes named above are each explained in the error-code reference.