Documentation

Rate limits

Each endpoint carries a per-minute and a per-day cap, set when it is minted. The defaults are 60/minute and 5,000/day, adjustable within 1–600 per minute and 1–200,000 per day. Zero is not a valid limit — an endpoint that can never be called should be revoked, not throttled to nothing.

What consumes a unit

Every tool call consumes one unit — including a call about to be refused for an unknown tool, a disabled tool or a lapsed entitlement, so probing cannot evade the cap. initialize, ping, tools/list and GET /api/v1/tools carry no tool invocation and consume nothing.

When a limit is consumed

A consumed limit answers HTTP 429 with a Retry-After header in seconds:

  • a per-minute denial points at the next minute boundary (1–60 seconds);
  • a per-day denial points at the next UTC midnight.

Over MCP the same condition is reported as JSON-RPC error -32002; over REST as 429 rate_limited. See Errors.

One counter, two doors

MCP and REST share ONE counter per endpoint — they are two doors onto the same pipeline, not two budgets.

Last modified on