# Rate limits

Each endpoint carries a per-minute and a per-day cap, set when it is minted. The defaults are
**60/minute** and **5,000/day**, adjustable within 1–600 per minute and 1–200,000 per day.
Zero is not a valid limit — an endpoint that can never be called should be revoked, not
throttled to nothing.

## What consumes a unit

**Every tool call consumes one unit** — including a call about to be refused for an unknown tool,
a disabled tool or a lapsed entitlement, so probing cannot evade the cap. `initialize`, `ping`,
`tools/list` and `GET /api/v1/tools` carry no tool invocation and consume nothing.

## When a limit is consumed

A consumed limit answers HTTP `429` with a **`Retry-After`** header in seconds:

- a per-minute denial points at the next minute boundary (1–60 seconds);
- a per-day denial points at the next UTC midnight.

Over MCP the same condition is reported as JSON-RPC error `-32002`; over REST as
`429 rate_limited`. See [Errors](/errors).

## One counter, two doors

MCP and REST share ONE counter per endpoint — they are two doors onto the same pipeline, not two
budgets.
