generated: '2026-09-06' method: searched source: >- https://developer.druva.com/docs/faqs, https://developer.druva.com/docs/request-and-response-structure, https://developer.druva.com/docs/event-apis, and every response object in the 19 first-party specifications in openapi/. replaces: >- This file previously held the 2026-05-04 API Evangelist scaffold, which asserted rate-limit tiers and X-RateLimit headers Druva has never published. That content was fabricated and has been removed. limit_count: 0 headers_published: false note: >- Druva publishes no rate limits. Searched the developer portal guides, the FAQ (which is where Druva puts its quantitative response rules), and all 970 published operations: no requests-per-second or per-minute figure, no burst allowance, no per-key or per-tenant quota, and no X-RateLimit-*, RateLimit-* or Retry-After header declared on any response. HTTP 429 is declared on exactly 2 of 970 operations (both in the MSP quota surface), so throttling clearly exists but is undocumented and unsignalled - a client cannot see it coming and cannot compute a backoff from the response. An honest zero. limits: [] response_headers: [] exhaustion_status: 429 exhaustion_note: >- Declared on 2 of 970 operations, described only as "Too many requests", with no Retry-After and no body schema stating when to retry. published_response_ceilings: note: >- These are the only quantitative response limits Druva does publish. They cap the SIZE of a response rather than the RATE of requests, which means an agent walking a large estate is bounded by page count, not by a documented request budget. ceilings: - scope: all APIs limit: 4097 unit: records per response overflow: nextPageToken returned; replay as pageToken source: https://developer.druva.com/docs/faqs - scope: inSync Events API limit: 500 unit: events per response overflow: Tracker identifier returned for the next call source: https://developer.druva.com/docs/faqs - scope: MSP quota configuration listing limit: 100 unit: records per page default: 50 note: pageSize must be between 1 and 100; pageToken cannot be combined with pageSize or customerIds. source: https://developer.druva.com/reference/listquotaconfigrequestfordoc token_ttl_as_de_facto_limit: note: >- The nearest thing to a published throttle is the access-token lifetime: 30 minutes on public cloud, 15 minutes on Endpoints and Data Governance GovCloud, non-extendable. A long-running agent must re-authenticate on that cadence. source: https://developer.druva.com/docs/faqs