Sigstore · Rate Limits

Sigstore Rate Limits

Sigstore's public-good Fulcio and Rekor instances do not publish formal per-client rate limits in the documentation overview; the project notes the service is operated as a public good and asks heavy consumers to self-host or run a private instance to protect shared capacity. Specific thresholds are not published as a developer-facing SLA.

Sigstore Rate Limits is the machine-readable rate-limit profile for Sigstore on the APIs.io network, conforming to the API Commons Rate Limits specification.

It captures 1 rate-limit definition, measuring varies.

The profile also includes 2 backoff/retry policies defined.

Tagged areas include Code Signing, PKI, Security, Open Source, and Rate Limiting.

1 Limits
Code SigningPKISecurityOpen SourceRate Limiting

Limits

Public-good fair use client
varies
not publicly documented
Public Fulcio and Rekor instances are operated as a public good; heavy users are encouraged to self-host rather than rely on a published throttle.

Policies

Public-Good Fair Use
Treat the public Sigstore instances as a shared public good. For high-volume signing or verification, self-host Fulcio/Rekor (or use a vendor-operated dedicated instance) rather than relying on the public service.
Self-Hosting for Scale
Sigstore is open source; production-critical workloads should run their own Fulcio and Rekor to control availability and avoid dependence on shared infrastructure.

Sources

Work with this as data

Every rate limit here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for rate limits

4 MCP tools reach this
  • find_rate_limitsBrowse and filter every rate limit in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This rate limit
curl "https://apis.io/api/v1/rate-limits/sigstore-rate-limits"
All rate limits
curl "https://apis.io/api/v1/rate-limits?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.