Rate limits and quotas
Each workspace has a monthly quota and a per-minute rate, set by its plan. Response headers show where you stand.
Limits belong to the workspace, not the key: every key in a workspace shares them.
| Plan | Requests a month | Requests a minute |
|---|---|---|
| Free | 10,000 | 30 |
| Starter | 600,000 | 60 |
| Pro | 6,000,000 | 300 |
Paid plans are not on sale yet, so new workspaces are on Free.
Monthly quota
Each answered lookup counts one request against the quota, and so does each page of a paged list.
| Counted | Not counted |
|---|---|
| A response with data, including an empty list | A refused request (any 4xx or 5xx) |
Each page of ip_domains, domain_history and lookup_asn | A lookup_ip answer for a private or reserved address (is_bogon: true) |
GET /v1/ping | GET /health, and listing the MCP server's tools |
| An MCP tool call that answers |
The Free plan's quota resets at the start of each calendar month, UTC. When the quota is used up, lookups answer 402
quota_exceeded until it resets.
A project can have its own monthly cap, set in the project's settings. It can only lower what the project may use of
the workspace's quota; when it is reached, that project's keys get 402 project_cap_exceeded.
Requests per minute
The rate is counted per UTC clock minute. Every request made with a valid key counts toward it, including refused
ones. Over the rate, requests get 429 rate_limited with a Retry-After header: wait that many seconds and
retry.
A separate limit protects keys: more than 100 refused or missing keys from one address in a minute also get 429.
IPv6 addresses count per /64.
Headers
Responses carry where you stand:
| Header | Meaning |
|---|---|
X-RateLimit-Limit | Requests allowed per minute. |
X-RateLimit-Remaining | Requests left this minute. |
X-RateLimit-Reset | When this minute's count resets, as Unix time in seconds. |
X-Quota-Limit | Requests allowed this month. |
X-Quota-Used | Requests used this month. |
X-Quota-Remaining | Requests left this month. |
X-Project-Quota-Limit, -Used, -Remaining | The same for the key's project, when it has a cap. |
The quota headers come on counted responses. When you get a 429, go by its Retry-After.