specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Authentik providerId: authentik generated: '2026-09-04' method: searched source: https://docs.goauthentik.io, https://goauthentik.io/pricing, openapi/_original/authentik-openapi.yml modified: '2026-09-04' created: '2026-05-04' limit_count: 0 headers: {} responseCodes: {} limits: [] description: 'authentik publishes NO API rate limits, and that is the correct finding rather than a gap in this profile. authentik is self-hosted open-source software: the operator runs the server, so throughput is bounded by their own infrastructure and reverse proxy, not by a vendor quota. The evidence is threefold and each part was checked directly.' evidence: - claim: No rate-limit response headers are declared in the contract. detail: A search of the published OpenAPI (openapi/_original/authentik-openapi.yml, 1,193 operations) finds no X-RateLimit-*, no RateLimit-*, and no Retry-After header on any operation. source: openapi/_original/authentik-openapi.yml - claim: No 429 response is declared anywhere. detail: 'The only response statuses declared across all 1,193 operations are 200 (868), 204 (184), 201 (141), 400 (1,193), 403 (1,193), 404 (15) and 500 (2). There is no 429 and no 503.' source: openapi/_original/authentik-openapi.yml - claim: No published quota on any commercial tier. detail: The pricing page prices per internal user per month and per external user per month. No request quota, burst ceiling or overage rate appears on any of the three tiers, and there is no hosted offering to meter. source: https://goauthentik.io/pricing status: 200 adjacent_throttling: note: 'authentik DOES ship request-throttling behaviour, but it protects authentication rather than the management API, and it is policy-driven and operator-configured rather than a published API limit. An agent will not encounter it on /api/v3 CRUD calls.' mechanisms: - name: Reputation policy description: Reacts to repeated failed authentication attempts from a username, a client IP, or both, lowering a reputation score that other policies can gate on. docs: https://docs.goauthentik.io/customize/policies/types/reputation - name: 2FA attempt throttling description: The Authenticator Validation stage throttles repeated failed attempts for TOTP, static, email and SMS OTP devices (email/SMS added in release 2026.5). docs: https://docs.goauthentik.io/add-secure-apps/flows-stages/stages/authenticator_validate agent_guidance: An agent integrating with an authentik deployment should apply its own client-side pacing and exponential backoff, and should treat a 500 as the signal to back off, since no 429 or Retry-After will ever be returned. Concurrency ceilings are whatever the operator's reverse proxy and worker pool impose. maintainers: - FN: Kin Lane email: kin@apievangelist.com