Rate Limits API usage limits and quotas
Understand rate limits for each plan and learn best practices for efficient API usage. Responses carry your per-minute burst (X-RateLimit-*) and, on metered calls, your monthly quota (X-Monthly-*).
No credit card required · Free API key
50
Free/Month
10K
Pro/Month
1M
Enterprise/Month
Key features. Everything you need to protect your infrastructure and users.
Per-Minute Limits
Burst limits to ensure fair usage and system stability.
Monthly Quotas
Total request allowance that resets monthly.
Rate Headers
Track the per-minute burst with X-RateLimit-* and the monthly quota with X-Monthly-* response headers.
Usage Dashboard
Monitor your usage in real-time from the dashboard.
429 Handling
Graceful error handling with retry-after guidance.
Custom Limits
Enterprise customers can request custom limits.
Use cases. How security teams use this tool.
Usage Monitoring
Track remaining quota to avoid unexpected limits.
Request Batching
Use bulk API to maximize efficiency.
Caching Strategy
Cache responses to reduce API calls.
Plan Selection
Choose the right plan for your volume.
Understanding API Rate Limits
Rate limits protect our infrastructure and ensure fair access for all users. We implement both per-minute burst limits and monthly quotas. Burst limits prevent any single user from overwhelming the system during peak usage, while monthly quotas align with subscription tiers. Understanding these limits helps you architect your integration for reliable operation under all conditions.
Monitoring Your API Usage
Every API response includes X-RateLimit headers for the per-minute burst: X-RateLimit-Limit is the burst allowance, X-RateLimit-Remaining what is left of it, and X-RateLimit-Reset when the window resets (in milliseconds since the Unix epoch). Responses that count against your monthly quota also carry X-Monthly-Usage, X-Monthly-Limit and X-Monthly-Percentage; that quota resets on the 1st at 00:00 UTC. Your dashboard provides historical usage graphs and alerts when approaching limits.
Handling Rate Limit Errors
When you exceed a limit, the API returns 429 Too Many Requests with a Retry-After header. A per-minute (burst) 429 clears within the minute: wait Retry-After seconds, then resume with backoff — the TypeScript SDK does this for you, up to its retries option. A monthly-quota 429 only clears on the 1st of next month at 00:00 UTC, so retrying before then spends nothing but time: stop, surface the error, and read the reset date and the upgrade options in the response body.
Tuning API Consumption
Reduce API calls by caching responses for frequently-queried entities, using bulk endpoints instead of multiple single lookups, and requesting only the data fields you need. Consider implementing local blocklists for known-malicious indicators to avoid redundant API calls. Enterprise customers can request custom rate limits tailored to their specific workload patterns.
Frequently asked questions.
What are the rate limits per plan?
How do I know my current usage?
What happens if I exceed the limit?
Can I request a rate limit increase?
Related articles. Learn more from our security research blog.
Ready to get started?
Join thousands of security teams using isMalicious to protect their infrastructure.
No credit card required · Free API key

