Portswigger Rate Limits
PortSwigger Burp Suite DAST APIs do not publish explicit per-minute or per-hour request rate limits in public documentation. The PAYS (Pay-as-you-scan) model enforces a default cap of 500 scan-hours per month, adjustable upon request. API access is gated by API key authentication and role-based permissions.
Portswigger Rate Limits is the machine-readable rate-limit profile for PortSwigger on the APIs.io network, conforming to the API Commons Rate Limits specification.
It captures 3 rate-limit definitions, measuring requests_per_minute and scan_hours_per_month.
The profile also includes response codes documented for throttled.
Tagged areas include Rate Limiting, DAST, and API Security.
Limits
Sources
- https://portswigger.net/burp/documentation/dast/user-guide/api-documentation
- https://portswigger.net/burp/account-and-subscription-management/pay-as-you-scan
Work with this as data
Every rate limit here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for rate limits
4 MCP tools reach this
find_rate_limitsBrowse and filter every rate limit in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/rate-limits/portswigger-rate-limits"
curl "https://apis.io/api/v1/rate-limits?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.