Portswigger Rate Limits
PortSwigger Burp Suite DAST APIs do not publish explicit per-minute or per-hour request rate limits in public documentation. The PAYS (Pay-as-you-scan) model enforces a default cap of 500 scan-hours per month, adjustable upon request. API access is gated by API key authentication and role-based permissions.
Portswigger Rate Limits is the machine-readable rate-limit profile for PortSwigger on the APIs.io network, conforming to the API Commons Rate Limits specification.
It captures 3 rate-limit definitions, measuring requests_per_minute and scan_hours_per_month.
The profile also includes response codes documented for throttled.
Tagged areas include Rate Limiting, DAST, and API Security.
Limits
Sources
- https://portswigger.net/burp/documentation/dast/user-guide/api-documentation
- https://portswigger.net/burp/account-and-subscription-management/pay-as-you-scan
Work with this as data
Every rate limit here is available over the APIs.io API and to AI agents over MCP.