See below for the rate limit policies for the Tier 20 (Development) Private Cloud subscription type.
APIBurst Request LimitSustained Request Limit
Authentication API2020/second
EndpointMethodBurst Request LimitSustained Request LimitLimit Type
User InfoGET, POST105/minuteTo a unique User ID
Change Password

Reset Password with Universal Login
POST101/minuteFrom an IP Address to a unique Email Address
Get Passwordless Code or LinkGET, POST5050/hourFrom an IP Address
Native Social Login (Apple / Facebook Only)POST50500/minuteAny Request for Apple or Facebook Native Social Login
Dynamic Application (Client) RegistrationPOST55/secondAny request
Universal LogoutPOST3535/secondAny request
Pushed Authorization Requests (PAR)POST100100/secondFrom an IP Address
Back-Channel authorize (CIBA)POST500500/minuteFrom an IP Address
Device code activation (no prompt)POST306/secondFrom an IP Address
Device code authorizationPOST55/secondFrom an IP Address
MFA OOB token exchangePOST1212/minuteTo a unique session
*Represents the default limit. You can configure the Signup endpoint limit in Auth0 Dashboard. To learn more, read Suspicious IP Throttling.
APIBurst Request LimitSustained Request Limit
Management API2020/second
EndpointMethodBurst Request LimitSustained Request LimitLimit Type
Read OrganizationsGET10100/minuteAny request
Read Organizations by IDGET40500/minuteAny request
Read Organizations by NameGET20200/minuteAny request
Write an OrganizationPOST, PATCH, DELETE5150/minuteAny request
Read Organization MembersGET40500/minuteAny request
Write Organization MembersPOST, DELETE20200/minuteAny request
Read Members of an OrganizationGET20200/minuteAny request
Read Organization Member RolesGET20200/minuteAny request
Write Organization Member RolesPOST, DELETE20200/minuteAny request
Read Organization ConnectionsGET10100/minuteAny request
Write Organization ConnectionsPOST, PATCH, DELETE5150/minuteAny request
Write Custom DomainPOST55/minuteAny request
Read Status ConnectionGET10015/secondAny request
Write Signing KeysPOST55/dayAny request
Read Partials for a PromptGET55/minuteAny request
Write Partials for a PromptPUT55/minuteAny request
Read Clients


Only applies to the usage of the q parameter.

GET5150/minuteAny request
Read Organization Client GrantsGET10100/minuteAny request
Write Organization Client GrantsPOST5150/minuteAny request
Limit TypeEndpoint PathOperationLimit
Single SCIM connection endpoint/scim/v2/connections/{connection-id}Any request25 requests per second
Global tenant limit for all SCIM connections/scim/v2/connections/*Any request100 requests per second
EndpointMethodBurst Request LimitSustained Request LimitLimit Type
Universal login prompts (global)GET, POST500500/minuteFrom an IP Address
Universal login prompts (per prompt)GET2010/minuteFrom an IP Address and state value.
Universal login prompts (per prompt)POST105/minuteFrom an IP Address
Password reset promptGET500500/minuteFrom an IP Address
MFA push enrollment promptGET, POST500500/minuteFrom an IP Address
MFA push challenge promptGET, POST500500/minuteFrom an IP Address
MFA SMS enrollment promptGET2010/minuteFrom an IP Address
MFA SMS enrollment promptPOST105/minuteFrom an IP Address
MFA SMS enrollment verify promptGET2010/minuteFrom an IP Address
MFA SMS enrollment verify promptPOST105/minuteFrom an IP Address
Passwordless SMS challenge promptGET, POST55/minuteFrom an IP Address
Passwordless email challenge promptGET, POST55/minuteFrom an IP Address
Phone verification enrollment promptGET, POST55/minuteFrom an IP Address
Phone verification challenge promptGET, POST55/minuteFrom an IP Address
Device code promptGET, POST55/secondFrom an IP Address
EndpointBurst Request LimitSustained Request LimitLimit TypeLimit
OTP (6 numeric digits) failures1010per hourTo a unique User ID
Recovery code failures1010per hourTo a unique User ID
Webauthn challenge failures1515per minuteTo a unique User ID
Webauthn challenge generated1515per minuteTo a unique User ID
Push notifications sent per user55per minuteTo a unique User ID
SMS sent per user101per hourTo a unique User ID
Email sent per user201per minuteTo a unique User ID