Rate Limits
RabbitQA does not apply a platform-wide request quota, and limits are not tied to a subscription plan. Two kinds of limit exist: a request-rate limit on AutoRunner traffic, and anti-abuse limits on the unauthenticated account endpoints.
Responses do not carry X-RateLimit-Limit, X-RateLimit-Remaining or X-RateLimit-Reset headers.
Do not build a client that depends on them.
AutoRunner request limits
Requests routed to /autorunner/api/v1/** and /qamaster/api/v1/** pass through a token-bucket limiter.
| Scope | Limit |
|---|---|
| All methods | 2,000 requests per minute |
GET only | 500 requests per minute |
Both buckets apply: a burst of reads is capped by the GET bucket first.
Counting is keyed per company and user for an authenticated caller, and per client IP otherwise.
AutoRunner test engines authenticating with X-Engine-Token bypass the limiter entirely, so a busy run does not consume a person's budget.
When a bucket is empty the gateway returns:
HTTP/1.1 429 Too Many Requests
Content-Type: application/problem+json
Retry-After: 60
{
"title": "Too Many Requests",
"status": 429,
"detail": "Too many requests. Please try again later"
}
Wait for the interval given in Retry-After before retrying.
The limiter keeps its buckets in memory on each AutoRunner instance rather than in shared storage. Across a multi-instance deployment the effective ceiling is higher than the numbers above, and it is not evenly distributed. Treat the figures as the per-instance guarantee, not a contract.
No equivalent request limiter runs on the Test Management, Organization, Device Farm or HealthCheck prefixes.
Account protection limits
These guard the unauthenticated endpoints and are enforced in shared storage across all instances.
| Action | Limit |
|---|---|
| Failed sign-in, per IP | 20 attempts per 15 minutes |
| Failed sign-in, per account | 5 attempts per 15 minutes |
| Password reset request, per email | 1 per minute |
| Password reset request, per IP | 10 per hour |
| Sign-up, per IP | 5 per hour by default, configurable per deployment |
Exceeding one of these returns 429.
Sign-in counters reset on a successful sign-in.
If the backing store is unreachable, the sign-up limiter fails open so that an outage in the anti-abuse layer cannot block legitimate registration.
Credit requests
Requests for additional credits are throttled per company and duplicate requests are suppressed, so repeatedly submitting the same request does not create additional approvals.
Staying within the limits
- Page through list endpoints with
pageandsizerather than fetching everything and filtering client-side. - Poll run status on an interval measured in seconds, not milliseconds; the
GETbucket is the tighter of the two. - Give automation its own service account so one runaway script cannot exhaust a team's shared budget — the AutoRunner limiter keys on company plus user.
- Honour
Retry-Afterinstead of retrying immediately.