Authelia Rate Limits
Authelia ships default per-endpoint rate limits, enabled by default, implemented as multiple overlapping token buckets per endpoint. These are anti-brute-force controls on a self-hosted server, not a commercial quota: they are per-deployment, configured by the operator, and every value below is the shipped default that the operator may raise, lower or disable. Distinct from Regulation, which silently bans users at the username/password form. REPLACES a 2026-05-04 bulk-sweep scaffold that recorded invented per-tier quotas and X-RateLimit-* headers Authelia does not send.
Authelia Rate Limits is the machine-readable rate-limit profile for Authelia on the APIs.io network, conforming to the API Commons Rate Limits specification.
It captures 11 rate-limit definitions.
Tagged areas include Authentication, Authorization, LDAP, MFA, and Open Source.
Limits
Work with this as data
Every rate limit here is available over the APIs.io API and to AI agents over MCP.