Hanko Rate Limits
Hanko applies per-operation token-bucket rate limits to sensitive authentication endpoints including OTP, passcode, and password operations. The default configuration allows 3 requests per 1-minute window per scope. Rate limits are configurable in self-hosted deployments via the backend configuration schema (v2.7.0+). Cloud-hosted deployments return HTTP 429 when limits are exceeded. Specific cloud-tier rate limit values are not publicly documented beyond the open-source defaults.
Hanko Rate Limits is the machine-readable rate-limit profile for Hanko on the APIs.io network, conforming to the API Commons Rate Limits specification.
It captures 3 rate-limit definitions, measuring requests_per_minute.
The profile also includes response codes documented for throttled.
Tagged areas include Rate Limiting, Authentication, and Passkeys.
Limits
Sources
- https://github.com/teamhanko/hanko/wiki/config-properties-rate_limiter-properties-token_limits
- https://docs.hanko.io
Work with this as data
Every rate limit here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for rate limits
4 MCP tools reach this
find_rate_limitsBrowse and filter every rate limit in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/rate-limits/hanko-rate-limits"
curl "https://apis.io/api/v1/rate-limits?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.