specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: AmTrust Financial Services providerId: amtrust-financial-services generated: '2026-09-02' created: '2026-05-04' modified: '2026-09-02' method: probed source: >- Live unauthenticated request to https://gateway.amtrustgroup.com/digital-bop/api/v1/agent-contacts, the nine harvested OpenAPI documents, and AmTrust's own Azure API Management product catalog at apimanagement.amtrustgroup.com — probed 2026-09-02 tags: - Commercial Insurance - Insurance - Rate Limiting - Quotas - Throttling limit_count: 0 limits: [] description: >- AmTrust publishes NO rate limits for any of the nine externally exposed APIs. All nine sit in the custom Azure API Management product "External", which states no call ceiling. No harvested OpenAPI document declares a 429 response — the full set of documented status codes across 387 operations is 200, 201, 400, 401, 403, 404 and 424 — and a live unauthenticated call to the gateway returned no RateLimit-*, X-RateLimit-* or Retry-After header. limit_count is 0 because that is the true published number. note: >- This artifact REPLACES a 2026-05-04 bulk-sweep scaffold that asserted free/professional/enterprise tiers at 10/100/1000 requests per minute with X-RateLimit-* headers and a 429 response. AmTrust publishes none of that: no 429 appears anywhere in the contract set, and the gateway emits no rate-limit headers. headers: limit: null remaining: null reset: null retryAfter: null policy: null note: No rate-limit signaling headers observed on the live gateway response. responseCodes: throttled: null note: >- No operation in any of the nine OpenAPI documents declares 429. Azure API Management returns 429 when a rate-limit policy is attached, but AmTrust's API-level policies are not anonymously readable (GET .../apis/digital-bop/policies/policy returned 401), so whether one is attached cannot be established from outside. observed_response: url: https://gateway.amtrustgroup.com/digital-bop/api/v1/agent-contacts method: GET status: 401 headers: WWW-Authenticate: AzureApiManagementKey realm="https://gateway.amtrustgroup.com/digital-bop",name="subscriber_id",type="header" Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Type: application/json body: '{ "statusCode": 401, "message": "Access denied due to missing subscription key. Make sure to include subscription key when making requests to an API." }' note: No rate-limit header of any family was present on the response. undocumented_tier_text: note: >- The APIM "Starter" product description reads "Subscribers will be able to run 5 calls/minute up to a maximum of 100 calls/week." That is Azure API Management's verbatim default sample text and NO AmTrust API is assigned to that product, so it is recorded here as observed but NOT counted as a published limit for any AmTrust API. source: https://apimanagement.amtrustgroup.com/.../amtrust-prod-apim/products?api-version=2022-08-01 maintainers: - FN: Kin Lane email: kin@apievangelist.com