See below for the rate limit policies for the Free subscription type.
APIBurst Request LimitSustained Request Limit
Authentication API300300/minute
EndpointMethodPathBurst Request LimitSustained Request LimitLimit Type
User InfoGET, POST/userinfo105 per/minTo a unique user ID
Change PasswordPOST/dbconnections/change_password & u/reset-password/request/:connection101 per/minFrom an IP address to a unique email address
Get Passwordless Code or LinkGET, POST/passwordless/start5050 per/hrFrom an IP address
Get TokenPOST/oauth/token3030 per/secAny request
Cross Origin AuthenticationPOSTco/authenticate55 per/secAny request
AuthenticationPOST/usernamepassword/login55 per/secAny request
JSON Web Token KeysGET/.well-known/jwks.json2020 per/secAny request
Native Social LoginPOST/oauth/token5050 per/minAny Request for Apple or Facebook Native Social Login
Dynamic Application (Client) RegistrationPOST/oidc/register55 per/secAny request
*Represents the default limit. You can configure the Signup endpoint limit in Auth0 Dashboard. To learn more, read Suspicious IP Throttling.
APIBurst Request LimitSustained Request Limit
Management22/second
EndpointMethodPathBurst Request LimitSustained Request LimitLimit Type
Register Dynamic ClientPOST/oidc/register55/secondAny request
Verify Custom DomainPOST/api/v2/custom-domains/verify55/minuteAny request
Read Status ConnectionPOST/api/v2/connections//status10015/secondAny request
Rotate Signing KeysPOST/api/v2/keys/signing/rotate55/dayAny request
Configure email templatesPOST, PATCH, DELETE/api/v2/email-templates525/minuteAny request
Read email templatesGET/api/v2/email-templates1050/minuteAny request
Configure email providerPOST, PATCH, DELETE/api/v2/emails/provider525/minuteAny request
Read email providerGET/api/v2/emails/provider525/minuteAny request