Rate limits on Users API

Tier: Free, Premium, Ultimate Offering: Self-managed
History

You can configure the per user rate limit for requests to Users API.

To change the rate limit:

  1. On the left sidebar, at the bottom, select Admin Area.
  2. Select Settings > Network.
  3. Expand Users API rate limit.
  4. In the Maximum requests per 10 minutes text box, enter the new value.
  5. Optional. In the Users to exclude from the rate limit box, list users allowed to exceed the limit.
  6. Select Save changes.

This limit is:

  • Applied independently per user.
  • Not applied per IP address.

The default value is 300.

Requests over the rate limit are logged into the auth.log file.

For example, if you set a limit of 300, requests to the GET /users/:id API endpoint exceeding a rate of 300 per 10 minutes are blocked. Access to the endpoint is allowed after ten minutes have elapsed.