generated: '2026-09-19' method: searched source: https://theloopbreaker.com/llms.txt description: >- llms.txt ("Rate Limits") is the only published statement: "All API endpoints return standard rate limit headers" — X-RateLimit-Limit 120 (requests per minute), X-RateLimit-Remaining, X-RateLimit-Reset (Unix timestamp), and Retry-After in seconds on 429. Live check 2026-09-19: 200 responses from GET /api/health, GET /api/hub/stats and GET /api/agent/status carried NONE of these headers (only Vercel cache/HSTS/CSP headers), so the runtime signal the docs promise was not observed. The number is recorded from the docs; the header absence is recorded as a finding. No burst, per-endpoint or per-key tiers are published (there are no keys). limit_count: 1 limits: - scope: per-client (undocumented key — no API keys exist; presumably per IP) window: 1 minute limit: 120 burst: null applies_to: all /api/* endpoints (per llms.txt) status_on_exhaustion: 429 headers: - {name: X-RateLimit-Limit, value: '120', observed_live: false} - {name: X-RateLimit-Remaining, value: requests left in current window, observed_live: false} - {name: X-RateLimit-Reset, value: Unix timestamp when the window resets, observed_live: false} - {name: Retry-After, value: seconds to wait (only on 429), observed_live: false} source: https://theloopbreaker.com/llms.txt observed: date: '2026-09-19' requests: - GET /api/health - GET /api/hub/stats - 'GET /api/agent/status?address=0xfA15...813C' rate_limit_headers_present: false other_headers: [cache-control, strict-transport-security, x-content-type-options, x-frame-options, x-vercel-cache, x-vercel-id] x402_timeout: 'Payment challenges carry maxTimeoutSeconds 60 — a payment window, not a rate limit.'