generated: '2026-08-14' method: probed source: >- Live unauthenticated responses from https://ciro.io and https://app.ciro.io, plus a search of ciro.io (site + sitemap.xml + provider-published llms.txt) for any developer documentation. note: >- Ciro documents no rate limits, because Ciro publishes no developer documentation and no public API at all. /docs, /api and /changelog all return 404 on the marketing origin; docs.ciro.io, developer.ciro.io, developers.ciro.io and api.ciro.io are NXDOMAIN. The only non-marketing HTTP surface reachable without credentials is the product application at app.ciro.io, whose internal /api/graphql answers HTTP 401 Unauthorized to an anonymous request and carries no rate-limit headers of any kind — no X-RateLimit-*, no RateLimit-*, no Retry-After. Whether limits are enforced behind that login cannot be observed without a customer session, and nothing is asserted about it. An honest zero with the headers actually checked, rather than an omission. limit_count: 0 limits: [] headers_observed: [] headers_checked: - X-RateLimit-Limit - X-RateLimit-Remaining - X-RateLimit-Reset - RateLimit-Limit - RateLimit-Remaining - RateLimit-Reset - RateLimit-Policy - Retry-After headers_result: >- None present on any probed response, on either the marketing origin or the application origin. exhaustion_status_code: unknown documented: false documentation_url: null x-evidence: - url: https://app.ciro.io/api/graphql status: 401 fetched: '2026-08-14' note: >- POST with a JSON body; body is "Unauthorized". Internal application endpoint, not a published API. No rate-limit headers in the response. - url: https://www.ciro.io/docs status: 404 fetched: '2026-08-14' - url: https://www.ciro.io/api status: 404 fetched: '2026-08-14' - url: https://ciro.io/llms.txt status: 200 fetched: '2026-08-14' note: >- Provider-published summary of the whole product. Names no API, no quota and no limit of any kind.