Skip to main content
Version: 1.0.8

Rate Limits

RabbitQA does not apply a platform-wide request quota, and limits are not tied to a subscription plan. Two kinds of limit exist: a request-rate limit on AutoRunner traffic, and anti-abuse limits on the unauthenticated account endpoints.

note

Responses do not carry X-RateLimit-Limit, X-RateLimit-Remaining or X-RateLimit-Reset headers. Do not build a client that depends on them.

AutoRunner request limits​

Requests routed to /autorunner/api/v1/** and /qamaster/api/v1/** pass through a token-bucket limiter.

ScopeLimit
All methods2,000 requests per minute
GET only500 requests per minute

Both buckets apply: a burst of reads is capped by the GET bucket first.

Counting is keyed per company and user for an authenticated caller, and per client IP otherwise. AutoRunner test engines authenticating with X-Engine-Token bypass the limiter entirely, so a busy run does not consume a person's budget.

When a bucket is empty the gateway returns:

HTTP/1.1 429 Too Many Requests
Content-Type: application/problem+json
Retry-After: 60

{
"title": "Too Many Requests",
"status": 429,
"detail": "Too many requests. Please try again later"
}

Wait for the interval given in Retry-After before retrying.

warning

The limiter keeps its buckets in memory on each AutoRunner instance rather than in shared storage. Across a multi-instance deployment the effective ceiling is higher than the numbers above, and it is not evenly distributed. Treat the figures as the per-instance guarantee, not a contract.

No equivalent request limiter runs on the Test Management, Organization, Device Farm or HealthCheck prefixes.

Account protection limits​

These guard the unauthenticated endpoints and are enforced in shared storage across all instances.

ActionLimit
Failed sign-in, per IP20 attempts per 15 minutes
Failed sign-in, per account5 attempts per 15 minutes
Password reset request, per email1 per minute
Password reset request, per IP10 per hour
Sign-up, per IP5 per hour by default, configurable per deployment

Exceeding one of these returns 429. Sign-in counters reset on a successful sign-in.

If the backing store is unreachable, the sign-up limiter fails open so that an outage in the anti-abuse layer cannot block legitimate registration.

Credit requests​

Requests for additional credits are throttled per company and duplicate requests are suppressed, so repeatedly submitting the same request does not create additional approvals.

Staying within the limits​

  • Page through list endpoints with page and size rather than fetching everything and filtering client-side.
  • Poll run status on an interval measured in seconds, not milliseconds; the GET bucket is the tighter of the two.
  • Give automation its own service account so one runaway script cannot exhaust a team's shared budget — the AutoRunner limiter keys on company plus user.
  • Honour Retry-After instead of retrying immediately.