API FundamentalsRate Limits

Rate Limits

Learn the Scrut API rate limits, the headers that report your usage, and how to handle a 429 response.

The Scrut API limits how many requests each credential can send in a 60-second window. Limits apply per credential, across all tokens issued from that credential.

Limits

EndpointLimit
Token endpoint10 requests per 60 seconds
Data endpoints (/v1/*)50 requests per 60 seconds

Heads Up! Requesting several tokens from the same credential doesn't raise your limit. All tokens from one credential share the same quota.

Rate Limit Headers

Responses include these headers:

HeaderDescription
X-RateLimit-LimitMaximum requests allowed in the current window
X-RateLimit-RemainingRequests remaining in the current window
X-RateLimit-ResetUnix timestamp, in seconds, when the window resets
Retry-AfterSeconds to wait before retrying. Returned only on a 429.

Handle a 429 Response

When you exceed a limit, the API returns 429:

  • Data endpoints return the error code rate_limit_exceeded.
  • The token endpoint returns the error code temporarily_unavailable.

Wait for the number of seconds in the Retry-After header, then retry the request. For write requests, retry with the same Idempotency-Key. See Idempotency.

import time
import requests

def get_with_retry(url, headers, params=None):
    while True:
        response = requests.get(url, headers=headers, params=params)
        if response.status_code != 429:
            return response
        time.sleep(int(response.headers.get("Retry-After", "1")))

Stay Within the Limits

  • Reuse an access token until it's close to expiring instead of requesting a new one for each call.
  • Use filters and the fields parameter to get what you need in one call instead of fetching records one by one. See Requests and Responses.
  • Set count=100 when you page through vulnerabilities to halve the number of requests.
  • Check X-RateLimit-Remaining and slow down before it reaches zero.

Contact support@scrut.io for further assistance.