Authelia Rate Limits
Authelia ships default per-endpoint rate limits, enabled by default, implemented as multiple overlapping token buckets per endpoint. These are anti-brute-force controls on a self-hosted server, not a commercial quota: they are per-deployment, configured by the operator, and every value below is the shipped default that the operator may raise, lower or disable. Distinct from Regulation, which silently bans users at the username/password form. REPLACES a 2026-05-04 bulk-sweep scaffold that recorded invented per-tier quotas and X-RateLimit-* headers Authelia does not send.
Authelia Rate Limits is the machine-readable rate-limit profile for Authelia on the APIs.io network, conforming to the API Commons Rate Limits specification.
It captures 11 rate-limit definitions.
Tagged areas include Authentication, Authorization, LDAP, MFA, and Open-Source.
Limits
Work with this as data
Every rate limit here is available over the APIs.io API and to AI agents over MCP.