specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: General Services Administration providerId: general-services-administration generated: '2026-09-12' created: '2026-05-04' modified: '2026-09-12' method: searched source: >- https://api.data.gov/docs/developer-manual/ (Web Service Rate Limits and DEMO_KEY Rate Limits) and https://open.gsa.gov/api/entity-api/ (SAM.gov API Key Rate Limits table). Replaces the 2026-05-04 scaffold, which carried invented "professional" and "enterprise" tiers GSA has never published. description: >- GSA runs two distinct rate-limit regimes. Everything behind api.gsa.gov / api.data.gov shares one API Umbrella hourly allowance per key. SAM.gov meters DAILY and by WHO holds the key — a non-federal user with no SAM.gov role gets 10 requests a day, while a federal system account gets 10,000. headers: limit: X-RateLimit-Limit remaining: X-RateLimit-Remaining reset: null retryAfter: null policy: null note: >- api.data.gov returns X-RateLimit-Limit and X-RateLimit-Remaining on every response. It publishes no reset header and no Retry-After; the documented recovery rule is that the hourly counter rolls off one hour after each request, so a client must infer the wait. responseCodes: throttled: 429 quotaExceeded: 429 errorCode: OVER_RATE_LIMIT limit_count: 8 limits: - tier: free name: api.data.gov default scope: api-key metric: requests_per_hour limit: 1000 timeFrame: hour window: rolling applies_to: >- Every API fronted by api.data.gov / api.gsa.gov — per diem, DAP analytics, Site Scanning, Search.gov results and clicks, CALC+, TMSS rate query, api.data.gov metrics, Data.gov CKAN, Regulations.gov. source: https://api.data.gov/docs/developer-manual/ - tier: anonymous name: DEMO_KEY hourly scope: ip-address metric: requests_per_hour limit: 30 timeFrame: hour applies_to: The shared DEMO_KEY used in GSA documentation examples. source: https://api.data.gov/docs/developer-manual/ - tier: anonymous name: DEMO_KEY daily scope: ip-address metric: requests_per_day limit: 50 timeFrame: day applies_to: The shared DEMO_KEY used in GSA documentation examples. source: https://api.data.gov/docs/developer-manual/ - tier: free name: SAM.gov — non-federal user with no SAM.gov role scope: api-key metric: requests_per_day limit: 10 timeFrame: day applies_to: SAM.gov personal API keys held by an unaffiliated public user. source: https://open.gsa.gov/api/entity-api/ - tier: free name: SAM.gov — non-federal user with a SAM.gov role scope: api-key metric: requests_per_day limit: 1000 timeFrame: day applies_to: SAM.gov personal API keys held by a registered entity user. source: https://open.gsa.gov/api/entity-api/ - tier: free name: SAM.gov — federal user scope: api-key metric: requests_per_day limit: 1000 timeFrame: day applies_to: SAM.gov personal API keys held by a federal user. source: https://open.gsa.gov/api/entity-api/ - tier: free name: SAM.gov — non-federal system account scope: system-account metric: requests_per_day limit: 1000 timeFrame: day applies_to: SAM.gov system account API keys. source: https://open.gsa.gov/api/entity-api/ - tier: free name: SAM.gov — federal system account scope: system-account metric: requests_per_day limit: 10000 timeFrame: day applies_to: SAM.gov system account API keys held by a federal system. source: https://open.gsa.gov/api/entity-api/ endpoint_specific: - api: general-services-administration:regulationsgov-api endpoint: /comments limits: - metric: requests_per_minute limit: 50 - metric: requests_per_hour limit: 500 result_cap: 5000 results per sequential query source: https://github.com/GSA-TTS/mcp-server-regulations-gov escalation: >- api.data.gov does not sell a higher tier. Its documented escalation path is to contact the agency that owns the specific API; there is no self-service upgrade and no paid plan.