Skip to main content
See below for the rate limits in the Private Cloud Performance 6000 RPS (60x) and 6000 RPS (60x) Burst subscription types. Therefore, we recommend deploying one tenant per private cloud environment for risk mitigation.
EndpointMethodBurst LimitSustained LimitLimit Type
Authentication API100100/secondGlobal
User InfoGET, POST105/minutePer User
Change Password / Reset PasswordPOST101/minutePer IP + Email
Get Passwordless Code or LinkGET, POST5050/hourPer IP
Native Social Login (Apple / Facebook)POST50500/minuteGlobal
Dynamic Application RegistrationPOST55/secondGlobal
Universal LogoutPOST3535/secondGlobal
Pushed Authorization Requests (PAR)POST100100/secondGlobal
Back-Channel Authorize (CIBA)POST500500/minuteGlobal
Device Code Activation (no prompt)POST306/secondGlobal
Device Code AuthorizationPOST55/secondGlobal
MFA OOB Token ExchangePOST1212/minuteGlobal
Custom Token ExchangePOST1515/secondGlobal
Write Token Exchange ProfilesPOST, PATCH, DELETE5100/secondGlobal
Read Token Exchange ProfilesGET20200/secondGlobal
DelegationPOST101/minuteGlobal
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
MGMT API Prod3,000180,000/minute
Organizations ReadGET6006,000/minute
User Organizations ReadGET2,40030,000/minute
Organizations by Name ReadGET1,20012,000/minute
Organizations WritePOST3009,000/minute
Org Members ReadGET2,40030,000/minute
Org Members WritePOST1,20012,000/minute
Org Invitation ReadGET1,20012,000/minute
Org Member Roles ReadGET1,20012,000/minute
Org Member Roles WritePOST1,20012,000/minute
Org Connections ReadGET6006,000/minute
Org Connections WritePOST3009,000/minute
Org Client Grants ReadPOST6006,000/minute
Org Client Grants WritePOST3009,000/minute
Clients Read Q QueryGET3009,000/minute
Extensions ReadGET3009,000/minute
Token Exchange Profiles ReadPOST1,20012,000/minute
Token Exchange Profiles WritePOST15300/minute
Users SearchGET1,200
Users WritePOST1,00025,000/minute
Effective Roles ReadGET6006,000/minute
Effective Permissions ReadGET6006,000/minute
Endpoint PathOperationLimit
Single SCIM connection endpoint/scim/v2/connections/{connection-id}Any request25 requests per second
Global tenant limit for all SCIM connections/scim/v2/connections/*Any request3000 requests per second
EndpointMethodBurst Request LimitSustained Request Limit
Universal login prompts (global)GET, POST500500/minute
Universal login prompts (per prompt)GET2010/minute
Universal login prompts (per prompt)POST105/minute
Password reset promptGET500500/minute
MFA push enrollment promptGET, POST500500/minute
MFA push challenge promptGET, POST500500/minute
MFA SMS enrollment promptGET2010/minute
MFA SMS enrollment promptPOST105/minute
MFA SMS enrollment verify promptGET2010/minute
MFA SMS enrollment verify promptPOST105/minute
Passwordless SMS challenge promptGET, POST55/minute
Passwordless email challenge promptGET, POST55/minute
Phone verification enrollment promptGET, POST55/minute
Phone verification challenge promptGET, POST55/minute
Device code promptGET, POST55/second
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Guardian by Tenant3,000
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Limit20
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Protection by Tenant6,000
Global by Prod Tenant6,000
Authorize (Prod)6,000
Authorize (Dev)3,000
Token Revocation (Prod)POST1,500
OAuth Custom Token ExchangePOST900
ROPG (Prod)POST3,000
Token Vault Global700
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Global Limit1,200
EndpointMethodBurst Limit (RPS)Sustained Limit (RPM)
Outer CreatePOST10
Outer GetGET120
Inner All30
Conf All20