specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Authologic providerId: authologic generated: '2026-09-14' method: searched source: https://developer.authologic.com/sitemap.xml (all 95 doc URLs), https://developer.authologic.com/docs/technical/implementation, openapi/authologic-customer-api-openapi.yml, and a live unauthenticated probe of https://sandbox.authologic.com/api/conversations created: '2026-05-04' modified: '2026-09-14' limit_count: 0 tags: - AML - Digital Identity - eID - Identity Verification - KYB - KYC - Liveness Check - Rate Limiting description: >- Authologic documents no rate limits and returns no rate-limit headers. This artifact records that measured absence, and the one real exhaustion signal the API does publish. It REPLACES a 2026-05-04 bulk-sweep scaffold that asserted per-tier limits (10/100/1000 rpm, monthly quotas, burst ceilings) and a full X-RateLimit-* header set — none of which Authologic publishes or returns. That scaffold was fabrication and has been removed rather than carried forward. limits: [] headers: observed: none documented: none note: >- No RateLimit-*, X-RateLimit-* or Retry-After header is declared anywhere in the OpenAPI (zero occurrences of "RateLimit", "429" or "Retry-After" in the 232KB document), and none was returned on a live probe. An agent has no runtime signal to back off against. responseCodes: quotaExceeded: 402 throttled: not published note: >- HTTP 402 is declared on all 14 operations as "Exhaustion of the plan or limitations related to non-payment". That is a commercial/plan exhaustion signal, not a per-window throttle, and it is the only exhaustion status in the contract. There is no 429 anywhere in the API. probe: url: https://sandbox.authologic.com/api/conversations method: POST status: 401 date: '2026-09-14' response_headers_seen: - 'www-authenticate: Basic realm="Realm"' - 'x-request-id: ' - 'x-content-type-options: nosniff' - 'x-frame-options: DENY' - 'cache-control: no-cache, no-store, max-age=0, must-revalidate' note: >- No rate-limit header of any kind on a live response. x-request-id IS returned and is useful for support correlation, but it is undocumented. findings: - >- No rate-limit, quota, throttling or fair-use page exists in the developer documentation. The 95-URL sitemap contains no such page, and the implementation notes — the natural home for it — cover only authentication, versioning and date formats. - >- Limits are almost certainly contractual rather than technical, consistent with the absence of public pricing (see plans/authologic-plans-pricing.yml, plan_count 0). maintainers: - FN: Kin Lane email: kin@apievangelist.com