# Rate limits transcribed from the provider's own documentation — see provenance. Quoted, not derived. generated: '2026-09-20' method: searched source: https://www.openproject.org/docs/installation-and-operations/configuration/ sources: - https://www.openproject.org/docs/installation-and-operations/configuration/ provenance: tool: planning/api-economics/harvest_ratelimits.py run: 20260920T133210 grounding: every limit_text was found verbatim in the fetched page text published: true note: Self-hosted configuration page; limits are configurable defaults via Rack::Attack (login burst 20/60s with 1800s ban, lost password 3/hour, API v3 6 per 3 seconds). Registration and mail recipient limits default to 0 (disabled). No rate-limit headers or HTTP status documented. limit_count: 3 limits: - name: Login brute-force protection limit_text: 20 POST /login requests for the same username within one minute limit: 20 window: minute scope: user endpoint: POST /login kind: burst - name: Lost password rate limiting limit_text: Limits password-reset requests per email address to 3 per hour. limit: 3 window: hour scope: user endpoint: password-reset - name: API v3 rate limiting limit_text: Limits API form endpoint requests per session to 6 per 3 seconds. limit: 6 scope: unclear endpoint: API form endpoints