Crowdstrike Rate Limits
CrowdStrike Falcon signals rate limiting on every response with X-Ratelimit-Limit and X-Ratelimit-Remaining, and returns HTTP 429 on exhaustion — 429 is a documented response on operations across the reference including POST /oauth2/token. The numeric ceiling is NOT published in prose anywhere on the public developer surface, but it is observable: an unauthenticated caller is served X-Ratelimit-Limit: 300 with a decrementing X-Ratelimit-Remaining on api.crowdstrike.com. Per-tenant and per-collection ceilings are stated only inside the authenticated Falcon console.
Crowdstrike Rate Limits is the machine-readable rate-limit profile for CrowdStrike on the APIs.io network, conforming to the API Commons Rate Limits specification.
It captures 2 rate-limit definitions, measuring requests and varies.
The profile also includes 4 backoff/retry policies defined and response codes documented for throttled, quotaExceeded, and serviceUnavailable.
Tagged areas include Cybersecurity, Endpoint Security, Rate Limiting, Quotas, and Throttling.
Limits
Policies
Sources
- https://developer.crowdstrike.com/api-reference/collections/oauth2/
- https://developer.crowdstrike.com/sdks/python/responses/
Work with this as data
Every rate limit here is available over the APIs.io API and to AI agents over MCP.