> ## Documentation Index
> Fetch the complete documentation index at: https://docs-dev-feat-sdk-reference-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> Rate limit policies for the Free Public subscription type.

# Free

See below for the rate limit policies for the Free subscription type.

<AccordionGroup>
  <Accordion title="Authentication API: Rate limits for the Authentication API and API endpoints in the Free subscription type.">
    | [API](/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy#api-rate-limits) | [Burst Request Limit](/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy#rate-limit-algorithm) | [Sustained Request Limit](/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy#rate-limit-algorithm) |
    | - | - | - |
    | Authentication API | 300 | 300/minute |

    | Endpoint | Method | Path | Burst Request Limit | Sustained Request Limit | Limit Type |
    | - | - | - | - | - | - |
    | User Info | GET, POST | `/userinfo` | 10 | 5 per/min | To a unique user ID |
    | Change Password | POST | `/dbconnections/change_password` & `u/reset-password/request/:connection` | 10 | 1 per/min | From an IP address to a unique email address |
    | Get Passwordless Code or Link | GET, POST | `/passwordless/start` | 50 | 50 per/hr | From an IP address |
    | Get Token | POST | `/oauth/token` | 30 | 30 per/sec | Any request |
    | Cross Origin Authentication | POST | `co/authenticate` | 5 | 5 per/sec | Any request |
    | Authentication | POST | `/usernamepassword/login` | 5 | 5 per/sec | Any request |
    | JSON Web Token Keys | GET | `/.well-known/jwks.json` | 20 | 20 per/sec | Any request |
    | Native Social Login | POST | `/oauth/token` | 50 | 50 per/min | Any Request for Apple or Facebook Native Social Login |
    | [Dynamic Application (Client) Registration](/docs/api/authentication/dynamic-application-client-registration/dynamic-application-registration) | POST | `/oidc/register` | 5 | 5 per/sec | Any request |
    | [On-Behalf-Of Token Exchange](/docs/secure/call-apis-on-users-behalf/on-behalf-of-token-exchange) | POST | `/oauth/token` | 2 | 2 per/sec | Any request |
    | [Cross App Access (ID-JAG exchange)](/docs/ai-agents-mcp/cross-app-access) | POST | `/oauth/token` | 5 | 5 per/sec | Any request |

    \*Represents the default limit. You can configure the Signup endpoint limit in Auth0 Dashboard. To learn more, read [Suspicious IP Throttling](/docs/secure/attack-protection/suspicious-ip-throttling).
  </Accordion>

  <Accordion title="Management API: Rate limits for the Management API on the Free subscription tier.">
    | API | Burst Request Limit | Sustained Request Limit |
    | - | - | - |
    | Management | 2 | 2/second |

    | Endpoint | Method | Path | Burst Request Limit | Sustained Request Limit | Limit Type |
    | - | - | - | - | - | - |
    | Register Dynamic Client | POST | `/oidc/register` | 5 | 5/second | Any request |
    | Verify Custom Domain | POST | `/api/v2/custom-domains{id}/verify` | 5 | 5/minute | Any request |
    | Read Status Connection | POST | `/api/v2/connections/{id}/status` | 100 | 15/second | Any request |
    | Rotate Signing Keys | POST | `/api/v2/keys/signing/rotate` | 5 | 5/day | Any request |
    | Configure email templates | POST, PATCH, DELETE | `/api/v2/email-templates` | 5 | 25/minute | Any request |
    | Read email templates | GET | `/api/v2/email-templates` | 10 | 50/minute | Any request |
    | Configure email provider | POST, PATCH, DELETE | `/api/v2/emails/provider` | 5 | 25/minute | Any request |
    | Read email provider | GET | `/api/v2/emails/provider` | 5 | 25/minute | Any request |
  </Accordion>

  <Accordion title="My Account API: Rate limits for the My Account API endpoints in the Free subscription type.">
    Each My Account API endpoint is covered by two rate limit policies: a per-tenant policy (scope: tenant, interval: second) as the primary guard, and a per-user policy (scope: tenant + user, interval: minute) as the secondary guard. A small number of policies are classified as endpoint\_params — they apply only when a specific query parameter is present (e.g. ?type=) and share their physical endpoint with a sibling policy.

    Tenant level:

    | Resource | Burst Limit | Sustained Limit | Refresh Rate | Scope |
    | - | - | - | - | - |
    | My Account API Rate Limit – Authentication Methods Read (Tenant Scope) | 2 | 2 | second | Tenant |
    | My Account API Rate Limit – Authentication Methods Read Filtered (Tenant Scope) | 5 | 5 | second | Tenant |
    | My Account API Rate Limit – Authentication Methods Write (Tenant Scope) | 2 | 2 | second | Tenant |
    | My Account API Rate Limit – Connected Accounts Create Flow (Tenant Scope) | 1 | 1 | second | Tenant |
    | My Account API Rate Limit – Connected Accounts Read Accounts (Tenant Scope) | 1 | 1 | second | Tenant |
    | My Account API Rate Limit – Connected Accounts Read Connections (Tenant Scope) | 1 | 1 | second | Tenant |
    | My Account API Rate Limit – Connected Accounts Write (Tenant Scope) | 1 | 1 | second | Tenant |
    | My Account API Rate Limit – Factors Read (Tenant Scope) | 25 | 25 | second | Tenant |
    | My Account API Rate Limit – Organizations Read (Tenant Scope) | 5 | 5 | second | Tenant |

    Tenant, User level:

    | Resource | Burst Limit | Sustained Limit | Refresh Rate | Scope |
    | - | - | - | - | - |
    | My Account API Rate Limit – Authentication Methods Read (User Scope) | 2 | 2 | minute | Tenant, User |
    | My Account API Rate Limit – Authentication Methods Read Filtered (User Scope) | 5 | 5 | minute | Tenant, User |
    | My Account API Rate Limit – Authentication Methods Write (User Scope) | 2 | 2 | minute | Tenant, User |
    | My Account API Rate Limit – Connected Accounts Create Flow (User Scope) | 10 | 10 | minute | Tenant, User |
    | My Account API Rate Limit – Connected Accounts Read Accounts (User Scope) | 5 | 5 | minute | Tenant, User |
    | My Account API Rate Limit – Connected Accounts Read Connections (User Scope) | 5 | 5 | minute | Tenant, User |
    | My Account API Rate Limit – Connected Accounts Write (User Scope) | 5 | 5 | minute | Tenant, User |
    | My Account API Rate Limit – Factors Read (User Scope) | 5 | 5 | minute | Tenant, User |
    | My Account API Rate Limit – Organizations Read (User Scope) | 1 | 1 | minute | Tenant, User |
  </Accordion>

  <Accordion title="SCIM API: Rate limits for the inbound SCIM API endpoints in Public cloud subscriptions that include Enterprise connections.">
    Connection and tenant limits are evaluated in order on every request: the connection limit is checked first, and the tenant limit is only checked if the connection limit is not exceeded.

    Connection, Tenant level:

    | Resource | Burst Limit | Sustained Limit | Refresh Rate | Scope |
    | - | - | - | - | - |

    Tenant level:

    | Resource | Burst Limit | Sustained Limit | Refresh Rate | Scope |
    | - | - | - | - | - |
    | SCIM API Rate Limit – Tenant Scope (applies across all SCIM endpoints) | 5 | 5 | second | Tenant |
  </Accordion>

  <Accordion title="My Organization API: Rate limits for the My Organization API in the Free subscription type.">
    Dual-level rate limiting: org bucket (primary, drives response headers) + tenant bucket (secondary ceiling across all orgs in a tenant).

    Tenant level:

    | Resource | Burst Limit | Sustained Limit | Refresh Rate | Scope |
    | - | - | - | - | - |
    | My Org API Rate Limit – Read Endpoints (Tenant Scope) | 8 | 4 | second | Tenant |
    | My Org API  Rate Limit – Write Endpoints (Tenant Scope) | 4 | 2 | second | Tenant |

    Organization level:

    | Resource | Burst Limit | Sustained Limit | Refresh Rate | Scope |
    | - | - | - | - | - |
    | My Org API Rate Limit – Read Endpoints (Organization Scope) | 8 | 4 | second | Organization |
    | My Org API  Rate Limit – Write Endpoints (Organization Scope) | 4 | 2 | second | Organization |
  </Accordion>
</AccordionGroup>
