{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Usage Limits"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"usage-limits","__idx":0},"children":["Usage Limits"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Titan Public API enforces rate limits at the gateway to keep the platform stable and give every organization a fair share."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"rate-limits","__idx":1},"children":["Rate limits"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Rate limits are enforced ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["per organization"]},", not per credential pair or per source IP. The bucket key is the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["org"]}," claim from the OIDC bearer token — every credential that resolves to the same organization shares one counter."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Kong evaluates a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["sliding window"]}," across three fixed sizes. A request is rejected as soon as ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["any"]}," of the three windows would be exceeded."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"production-limits","__idx":2},"children":["Production limits"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Window"},"children":["Window"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Requests"},"children":["Requests"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Per minute"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["300"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Per hour"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3,000"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Per day"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["30,000"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The stricter window wins — a burst that fits under the per-hour cap can still be rejected if it exceeds the per-minute cap."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"response-headers","__idx":3},"children":["Response headers"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Every response carries the current limit state so you can back off proactively:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Header"},"children":["Header"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Meaning"},"children":["Meaning"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["RateLimit-Limit"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Ceiling for the current window."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["RateLimit-Remaining"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Requests remaining in the current window."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["RateLimit-Reset"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Seconds until the current window resets."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Retry-After"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Present only on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["429"]},". Seconds to wait before retrying."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"when-you-hit-the-limit","__idx":4},"children":["When you hit the limit"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The gateway returns ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["429 Too Many Requests"]}," with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Retry-After"]}," header. Honour it — or use exponential backoff starting at 1 second, capped at 60 seconds. Retries without backoff amplify congestion and can lead to sustained throttling of your organization."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"scope-note","__idx":5},"children":["Scope note"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["These limits cover the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Public API"]}," surface only: routes under ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/public/<major>/*"]},". Adjacent endpoints (OAuth token issuance, internal routes) have their own separately-tuned limits and are not part of the public contract."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"getting-more-headroom","__idx":6},"children":["Getting more headroom"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Contact your SecurityScorecard account team. Include:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Your organization identifier (never credential secrets)."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The endpoints and request volume you expect."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Whether the traffic is steady or bursty."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Do not attempt to work around limits by rotating credentials or sourcing from multiple IPs — the counter is keyed by organization, and coordinated evasion is treated as abuse."]}]},"headings":[{"value":"Usage Limits","id":"usage-limits","depth":1},{"value":"Rate limits","id":"rate-limits","depth":2},{"value":"Production limits","id":"production-limits","depth":3},{"value":"Response headers","id":"response-headers","depth":3},{"value":"When you hit the limit","id":"when-you-hit-the-limit","depth":3},{"value":"Scope note","id":"scope-note","depth":2},{"value":"Getting more headroom","id":"getting-more-headroom","depth":2}],"frontmatter":{"seo":{"title":"Usage Limits"}},"lastModified":"2026-08-19T12:45:50.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/docs/guides/usage-limits","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}