Fortify Rate Limits
Fortify on Demand exposes a REST API at api.emea.fortify.com / api.ams.fortify.com / api.apac.fortify.com with OAuth2 client credentials. OpenText does not publish numeric per-second rate limits in the public docs; throttles are per-tenant and oriented around long-running scan submission and result-retrieval operations. Self-managed Fortify SSC has no platform-imposed API limit.
Fortify Rate Limits is the machine-readable rate-limit profile for Fortify on the APIs.io network, conforming to the API Commons Rate Limits specification.
It captures 2 rate-limit definitions, measuring varies and requests_per_second.
The profile also includes 4 backoff/retry policies defined and response codes documented for throttled and serviceUnavailable.
Tagged areas include Application Security, DAST, SAST, SCA, and Rate Limiting.
Limits
Policies
Sources
Work with this as data
Every rate limit here is available over the APIs.io API and to AI agents over MCP.