Rate Limits
Learn the Scrut API rate limits, the headers that report your usage, and how to handle a 429 response.
The Scrut API limits how many requests each credential can send in a 60-second window. Limits apply per credential, across all tokens issued from that credential.
Limits
| Endpoint | Limit |
|---|---|
| Token endpoint | 10 requests per 60 seconds |
Data endpoints (/v1/*) | 50 requests per 60 seconds |
Heads Up! Requesting several tokens from the same credential doesn't raise your limit. All tokens from one credential share the same quota.
Rate Limit Headers
Responses include these headers:
| Header | Description |
|---|---|
X-RateLimit-Limit | Maximum requests allowed in the current window |
X-RateLimit-Remaining | Requests remaining in the current window |
X-RateLimit-Reset | Unix timestamp, in seconds, when the window resets |
Retry-After | Seconds to wait before retrying. Returned only on a 429. |
Handle a 429 Response
When you exceed a limit, the API returns 429:
- Data endpoints return the error code
rate_limit_exceeded. - The token endpoint returns the error code
temporarily_unavailable.
Wait for the number of seconds in the Retry-After header, then retry the request. For write requests, retry with the same Idempotency-Key. See Idempotency.
import time
import requests
def get_with_retry(url, headers, params=None):
while True:
response = requests.get(url, headers=headers, params=params)
if response.status_code != 429:
return response
time.sleep(int(response.headers.get("Retry-After", "1")))
Stay Within the Limits
- Reuse an access token until it's close to expiring instead of requesting a new one for each call.
- Use filters and the
fieldsparameter to get what you need in one call instead of fetching records one by one. See Requests and Responses. - Set
count=100when you page through vulnerabilities to halve the number of requests. - Check
X-RateLimit-Remainingand slow down before it reaches zero.
Contact support@scrut.io for further assistance.