Every response carries X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset (Unix time, in seconds, when the current window ends). Each key may make 600 requests per minute. Summaries that are expensive to compute also have a per-client budget, and the headers then report that tighter budget:
| Endpoint | Per client, per minute |
|---|---|
GET /clients/{client_id}/risk | 20 |
GET /clients/{client_id}/phishing/summary | 30 |
GET /clients/{client_id}/dark-web | 30 |
GET /clients/{client_id} | 60 |
GET /users/{user_id}/risk | 120 |
Client summaries and risk are cached for a few minutes, so calling them more often returns the same numbers. To read every user's score, page through GET /clients/{client_id}/users, which carries each score, rather than calling /users/{user_id}/risk per user.