1. Partner API v2
  2. Guides
  3. Rate limits
Guide

Rate limits

Per-key and per-client budgets, the headers that report them, and caching.

Every response carries X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset (Unix time, in seconds, when the current window ends). Each key may make 600 requests per minute. Summaries that are expensive to compute also have a per-client budget, and the headers then report that tighter budget:

EndpointPer client, per minute
GET /clients/{client_id}/risk20
GET /clients/{client_id}/phishing/summary30
GET /clients/{client_id}/dark-web30
GET /clients/{client_id}60
GET /users/{user_id}/risk120

Client summaries and risk are cached for a few minutes, so calling them more often returns the same numbers. To read every user's score, page through GET /clients/{client_id}/users, which carries each score, rather than calling /users/{user_id}/risk per user.