name: ProcessMaker API Rate Limits description: ProcessMaker does not publicly document specific rate limits for its Platform RESTful API. Rate limits may be applied at the instance or plan level and are typically managed through the platform's server configuration. Organizations on cloud plans should contact ProcessMaker support for specific rate limit policies applicable to their subscription tier. url: https://processmaker.gitbook.io/developer-documentation rateLimits: - scope: Platform API description: Rate limits are not publicly specified for the ProcessMaker Platform RESTful API. Limits depend on the deployment type (cloud vs on-premise) and the subscription plan. documented: false notes: - Cloud-hosted instances may have infrastructure-level rate limiting - On-premise deployments are self-managed and rate limits depend on server configuration - Contact ProcessMaker support for specific rate limit policies authentication: - type: OAuth 2.0 description: ProcessMaker uses OAuth 2.0 for API authentication with multiple grant types supported. grantTypes: - name: Personal API Access Token description: Bearer tokens generated by users or administrators, bypassing the full OAuth handshake. Best for direct API testing and scripting. endpoint: N/A - Generated in user settings - name: Client Credentials Grant description: For service-to-service communication where user authentication is not required. endpoint: POST /oauth/token parameters: - grant_type=client_credentials - client_id - client_secret - scope (optional) - name: Authorization Code Grant description: For interactive web and mobile applications with user login and permission approval flow. authorizationEndpoint: GET /oauth/authorization tokenEndpoint: POST /oauth/token parameters: - client_id - response_type - redirect_uri - type: Bearer Token description: All API requests use Bearer token authentication in the Authorization header. format: 'Authorization: Bearer {token}' setup: - description: Authentication clients must be created in the Administration panel under Auth Clients, requiring a unique name and redirect URL configuration. url: https://github.com/ProcessMaker/processmaker/wiki/API-Authentication