generated: '2026-09-19' method: probed source: https://api.decision-anchor.com/v1/pricing/current docs: - https://api.decision-anchor.com/openapi.json - https://github.com/zse4321/decision-anchor-sdk/blob/main/AGENTS.md limit_count: 2 summary: >- Decision Anchor signals its request rate limit at runtime with the IETF RateLimit header fields on every response from api.decision-anchor.com — observed live and unauthenticated on 2026-09-19 as a policy of 100 requests per 60-second window — but declares neither the headers nor the number anywhere in its OpenAPI or docs. The contract does declare one route-specific limit: 5 recovery attempts per 15 minutes on POST /v1/agent/token/recover (429). Beyond request rate, the environment's throttles are economic (DAC cost per record, the owner-set DAB spending cap) rather than counts. headers: limit: RateLimit-Limit policy: RateLimit-Policy remaining: RateLimit-Remaining reset: RateLimit-Reset retry_after: not observed observed: - {url: 'GET https://api.decision-anchor.com/v1/pricing/current', fetched: '2026-09-19', headers: 'ratelimit-limit: 100; ratelimit-policy: 100;w=60; ratelimit-remaining: 98; ratelimit-reset: 58'} - {url: 'GET https://api.decision-anchor.com/v1/agent/register', fetched: '2026-09-19', headers: 'ratelimit-limit: 100; ratelimit-policy: 100;w=60; ratelimit-remaining: 94; ratelimit-reset: 57', note: remaining decremented across five sequential requests within one window, so the counter is per client, not per route} note: 'Header form matches draft-ietf-httpapi-ratelimit-headers (RateLimit-Policy "100;w=60"). Not declared in the OpenAPI components.headers.' rate_limits: - name: Requests per client window scope: per-client (keyed before authentication — observed on unauthenticated GETs) limit: 100 window: 60s metric: request burst: null headers: [RateLimit-Limit, RateLimit-Policy, RateLimit-Remaining, RateLimit-Reset] exhaustion_status: 429 (inferred from the header family; exhaustion not observed) source: live response headers, 2026-09-19 documented: false - name: Token recovery attempts scope: per-route limit: 5 window: 15 minutes metric: request applies_to: ['POST /v1/agent/token/recover'] exhaustion_status: 429 source: 'openapi POST /v1/agent/token/recover 429 description "Rate limit exceeded (5 per 15 minutes)"; description "Strictly rate-limited."' documented: true economic_limits: - {name: DAB (Decision Anchor Budget), scope: per-agent, set_by: owner via PUT /dap/dab/set, effect: 'external DAC spending across DD/EE, sDAC, ISE and paid ARA is rejected once the cap is reached; a subordinate agent cannot raise it (GET /v1/dab/status to read)', source: AGENTS.md "Owner and DAB"} - {name: Trial balance, scope: per-agent, limit: 500 DAC / 30 days, source: '/.well-known/x402.json trial'} - {name: Earned DAC min_spend, scope: per-agent, limit: 30 DAC minimum accumulation before use, source: 'GET /v1/pricing/current earned_dac'} - {name: DD direct-access quota, scope: per-record, limit: 'ee_direct_access_quota (default 10 reads) within ee_direct_access_period (default 30d)', source: AGENTS.md} - {name: ASA subscription periods, scope: per-agent, limit: max_periods 12 of 90 days, source: 'GET /v1/pricing/current asa'} time_limits: - {name: External-payment confirmation window, limit: 30 minutes after DD create, exhaustion_status: 410 PAYMENT_EXPIRED, source: 'openapi POST /v1/dd/confirm'} - {name: Anomaly-compare comparison window, limit: 'period_days, default 90', source: AGENTS.md} exhaustion: status: 429 headers: [RateLimit-Reset] media_type: application/json note: 'Only the recovery route documents 429 in the contract. The global policy''s 429 body shape is not published; assume the {error_code, message} envelope.' undocumented: - 'GET /dap/system/limits ("Get system limits", owner session) exists but is behind the portal login and was not probed; it likely enumerates account-level caps.'