Skip to content
Private preview: new accounts are by invitation only. Ask for one

Rate limits and quotas

Each workspace has a monthly quota and a per-minute rate, set by its plan. Response headers show where you stand.

Limits belong to the workspace, not the key: every key in a workspace shares them.

PlanRequests a monthRequests a minute
Free10,00030
Starter600,00060
Pro6,000,000300

Paid plans are not on sale yet, so new workspaces are on Free.

Monthly quota

Each answered lookup counts one request against the quota, and so does each page of a paged list.

CountedNot counted
A response with data, including an empty listA refused request (any 4xx or 5xx)
Each page of ip_domains, domain_history and lookup_asnA lookup_ip answer for a private or reserved address (is_bogon: true)
GET /v1/pingGET /health, and listing the MCP server's tools
An MCP tool call that answers

The Free plan's quota resets at the start of each calendar month, UTC. When the quota is used up, lookups answer 402 quota_exceeded until it resets.

A project can have its own monthly cap, set in the project's settings. It can only lower what the project may use of the workspace's quota; when it is reached, that project's keys get 402 project_cap_exceeded.

Requests per minute

The rate is counted per UTC clock minute. Every request made with a valid key counts toward it, including refused ones. Over the rate, requests get 429 rate_limited with a Retry-After header: wait that many seconds and retry.

A separate limit protects keys: more than 100 refused or missing keys from one address in a minute also get 429. IPv6 addresses count per /64.

Headers

Responses carry where you stand:

HeaderMeaning
X-RateLimit-LimitRequests allowed per minute.
X-RateLimit-RemainingRequests left this minute.
X-RateLimit-ResetWhen this minute's count resets, as Unix time in seconds.
X-Quota-LimitRequests allowed this month.
X-Quota-UsedRequests used this month.
X-Quota-RemainingRequests left this month.
X-Project-Quota-Limit, -Used, -RemainingThe same for the key's project, when it has a cap.

The quota headers come on counted responses. When you get a 429, go by its Retry-After.

On this page