generated: '2026-08-04' method: searched source: >- openapi/malwarebytes-threatdown-nebula-openapi.json (info.description "Rate Limiting" section), openapi/malwarebytes-threatdown-oneview-openapi.json summary: >- ThreatDown documents one platform-wide quota in the OpenAPI description for both the Nebula and OneView APIs: a leaky-bucket limiter with a default of 360 requests per minute per application, returning HTTP 429 on exhaustion. The quota is negotiable with ThreatDown per application. rate_limits: - api: ThreatDown Nebula API scope: per OAuth2 application limit_count: 360 limit_unit: requests interval: minute algorithm: leaky bucket exceeded_status: 429 negotiable: true source: openapi/malwarebytes-threatdown-nebula-openapi.json evidence: >- "ThreatDown API implements a rate-limiting mechanism to prevent abuse. The rate-limiting mechanism is implemented using a leaky bucket algorithm. Once you exceed the available limit, our server will respond with a `429` status code. ... Currently, the default available quota is `360` requests per minute." - api: ThreatDown OneView API scope: per OAuth2 application limit_count: 360 limit_unit: requests interval: minute algorithm: leaky bucket exceeded_status: 429 negotiable: true source: openapi/malwarebytes-threatdown-oneview-openapi.json signalling: response_headers_documented: false headers: ratelimit_limit: null ratelimit_remaining: null ratelimit_reset: null retry_after: null rfc9239_ratelimit_headers: false note: >- No rate-limit response headers are documented and none are declared in either OpenAPI definition — the 429 status code itself is not declared as a response on any of the 841 operations. A client cannot read remaining quota or a reset time; it can only observe the 429 and back off blindly. guidance_published: - Subscribe to webhook events instead of polling the API to react to changes. - Throttle requests so the limit is not exceeded. - Batch requests where possible. - Contact ThreatDown to request an increased API quota for the application. retry: documented_strategy: >- "You can throttle your requests and retry them later." No backoff algorithm, jitter guidance or maximum-retry recommendation is given for API requests. (Exponential backoff with a default of 5 retries IS documented, but for ThreatDown's own delivery of webhooks to your endpoint — see asyncapi/malwarebytes-threatdown-webhooks.yml.) gaps: - No RateLimit-Limit / RateLimit-Remaining / RateLimit-Reset or Retry-After headers documented. - 429 is not declared as a response on any operation in either OpenAPI definition. - No per-endpoint or per-resource sub-limits published; one global figure covers 841 operations. - No published burst capacity or bucket-refill rate for the leaky-bucket implementation.