generated: '2026-09-13' method: searched source: |- Published verbatim in the OpenAPI info.description "Rate limits" section (openapi/routebase-public-api-openapi.json) and the docs at https://docs.routebase.dev/api-keys/. Not observed on a live 429 (auth-gated API), so method is the documented policy, not a probed header capture. docs: https://docs.routebase.dev/ window_note: Counted in a rolling window of 60 seconds. status_on_exhaustion: '429' response_headers: - name: Retry-After note: |- Returned on 429. A polling CI job should honour it rather than retry immediately. No RateLimit-*/X-RateLimit-* limit/remaining/reset headers are documented in the spec or docs — only Retry-After signals exhaustion. limits: - scope: per-api-key-user window_seconds: 60 limit: 100 detail: |- A call authenticated with an API key (X-API-Key, rb_live_) gets 100 requests per rolling 60s window, counted per user of that key. - scope: per-source-ip window_seconds: 60 limit: null detail: |- SCIM (/scim/v2) is counted per source IP instead of per user, so every call from one identity provider shares a single budget. The numeric per-IP ceiling is not published; recorded as null rather than guessed. limit_count: 2 note: |- Two documented rate-limit scopes (API-key-per-user and SCIM-per-source-IP). Exhaustion answers 429 with Retry-After. See conventions/routebase-conventions.yml (rate_limit_signaling).