Skip to main content
See below for the rate limit policies for the Tier 20 (Development) Private Cloud subscription type.
EndpointMethodBurst LimitSustained LimitLimit Type
Authentication API100100/secondGlobal
User InfoGET, POST105/minutePer User
Change Password / Reset PasswordPOST101/minutePer IP + Email
Get Passwordless Code or LinkGET, POST5050/hourPer IP
Native Social Login (Apple / Facebook)POST50500/minuteGlobal
Dynamic Application RegistrationPOST55/secondGlobal
Universal LogoutPOST3535/secondGlobal
Pushed Authorization Requests (PAR)POST100100/secondGlobal
Back-Channel Authorize (CIBA)POST500500/minuteGlobal
Device Code Activation (no prompt)POST306/secondGlobal
Device Code AuthorizationPOST55/secondGlobal
MFA OOB Token ExchangePOST1212/minuteGlobal
Custom Token ExchangePOST1515/secondGlobal
Write Token Exchange ProfilesPOST, PATCH, DELETE5100/secondGlobal
Read Token Exchange ProfilesGET20200/secondGlobal
DelegationPOST101/minuteGlobal
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
MGMT API Prod201,200/minute
Organizations ReadGET10100/minute
User Organizations ReadGET40500/minute
Organizations by Name ReadGET20200/minute
Organizations WritePOST5150/minute
Org Members ReadGET40500/minute
Org Members WritePOST20200/minute
Org Invitation ReadGET20200/minute
Org Member Roles ReadGET20200/minute
Org Member Roles WritePOST20200/minute
Org Connections ReadGET10100/minute
Org Connections WritePOST5150/minute
Org Client Grants ReadPOST10100/minute
Org Client Grants WritePOST5150/minute
Clients Read Q QueryGET5150/minute
Extensions ReadGET5150/minute
Token Exchange Profiles ReadPOST880/minute
Token Exchange Profiles WritePOST5100/minute
Users SearchGET20
Users WritePOST15500/minute
Effective Roles ReadGET10100/minute
Effective Permissions ReadGET10100/minute
Endpoint PathOperationLimit
Single SCIM connection endpoint/scim/v2/connections/{connection-id}Any request25 requests per second
Global tenant limit for all SCIM connections/scim/v2/connections/*Any request100 requests per second
EndpointMethodBurst Request LimitSustained Request Limit
Universal login prompts (global)GET, POST500500/minute
Universal login prompts (per prompt)GET2010/minute
Universal login prompts (per prompt)POST105/minute
Password reset promptGET500500/minute
MFA push enrollment promptGET, POST500500/minute
MFA push challenge promptGET, POST500500/minute
MFA SMS enrollment promptGET2010/minute
MFA SMS enrollment promptPOST105/minute
MFA SMS enrollment verify promptGET2010/minute
MFA SMS enrollment verify promptPOST105/minute
Passwordless SMS challenge promptGET, POST55/minute
Passwordless email challenge promptGET, POST55/minute
Phone verification enrollment promptGET, POST55/minute
Phone verification challenge promptGET, POST55/minute
Device code promptGET, POST55/second
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Guardian by Tenant20
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Limit20
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Protection by Tenant20
Global by Prod Tenant20
Authorize (Prod)20
Authorize (Dev)20
Token Revocation (Prod)POST5
OAuth Custom Token ExchangePOST3
ROPG (Prod)POST20
Token Vault Global10
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Limit20
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Outer CreatePOST10
Outer GetGET120
Inner All30
Conf All20