Skip to main content
See below for the rate limits in the Private Cloud Performance 500 RPS (5x) subscription type. These limits apply to each tenant you create in the private cloud environment.  Therefore, we recommend deploying one tenant per private cloud environment for risk mitigation.
EndpointMethodBurst LimitSustained LimitLimit Type
Authentication API100100/secondGlobal
User InfoGET, POST105/minutePer User
Change Password / Reset PasswordPOST101/minutePer IP + Email
Get Passwordless Code or LinkGET, POST5050/hourPer IP
Native Social Login (Apple / Facebook)POST50500/minuteGlobal
Dynamic Application RegistrationPOST55/secondGlobal
Universal LogoutPOST3535/secondGlobal
Pushed Authorization Requests (PAR)POST100100/secondGlobal
Back-Channel Authorize (CIBA)POST500500/minuteGlobal
Device Code Activation (no prompt)POST306/secondGlobal
Device Code AuthorizationPOST55/secondGlobal
MFA OOB Token ExchangePOST1212/minuteGlobal
Custom Token ExchangePOST1515/secondGlobal
Write Token Exchange ProfilesPOST, PATCH, DELETE5100/secondGlobal
Read Token Exchange ProfilesGET20200/secondGlobal
DelegationPOST101/minuteGlobal
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
MGMT API Prod25015,000/minute
Organizations ReadGET50500/minute
User Organizations ReadGET2002,500/minute
Organizations by Name ReadGET1001,000/minute
Organizations WritePOST25750/minute
Org Members ReadGET2002,500/minute
Org Members WritePOST1001,000/minute
Org Invitation ReadGET1001,000/minute
Org Member Roles ReadGET1001,000/minute
Org Member Roles WritePOST1001,000/minute
Org Connections ReadGET50500/minute
Org Connections WritePOST25750/minute
Org Client Grants ReadPOST50500/minute
Org Client Grants WritePOST25750/minute
Clients Read Q QueryGET25750/minute
Extensions ReadGET25750/minute
Token Exchange Profiles ReadPOST1001,000/minute
Token Exchange Profiles WritePOST15300/minute
Users SearchGET150
Users WritePOST1005,000/minute
Effective Roles ReadGET50500/minute
Effective Permissions ReadGET50500/minute
Endpoint PathOperationLimit
Single SCIM connection endpoint/scim/v2/connections/{connection-id}Any request25 requests per second
Global tenant limit for all SCIM connections/scim/v2/connections/*Any request250 requests per second
EndpointMethodBurst Request LimitSustained Request Limit
Universal login prompts (global)GET, POST500500/minute
Universal login prompts (per prompt)GET2010/minute
Universal login prompts (per prompt)POST105/minute
Password reset promptGET500500/minute
MFA push enrollment promptGET, POST500500/minute
MFA push challenge promptGET, POST500500/minute
MFA SMS enrollment promptGET2010/minute
MFA SMS enrollment promptPOST105/minute
MFA SMS enrollment verify promptGET2010/minute
MFA SMS enrollment verify promptPOST105/minute
Passwordless SMS challenge promptGET, POST55/minute
Passwordless email challenge promptGET, POST55/minute
Phone verification enrollment promptGET, POST55/minute
Phone verification challenge promptGET, POST55/minute
Device code promptGET, POST55/second
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Guardian by Tenant250
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Limit20
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Protection by Tenant500
Global by Prod Tenant500
Authorize (Prod)500
Authorize (Dev)250
Token Revocation (Prod)POST125
OAuth Custom Token ExchangePOST75
ROPG (Prod)POST180
Token Vault Global240
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Limit250
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Outer CreatePOST10
Outer GetGET120
Inner All30
Conf All20