Zitadel Rate Limits
ZITADEL Cloud applies IP-oriented rate limits, with separate ceilings for the login / register / reset UI paths and for all other gRPC / REST / OAuth API endpoints. DDoS mitigation is layered on top, so simply rotating IPs to evade limits can lead to blocking. Self-hosted ZITADEL has no enforced ceiling.
Zitadel Rate Limits is the machine-readable rate-limit profile for Zitadel on the APIs.io network, conforming to the API Commons Rate Limits specification.
It captures 2 rate-limit definitions, measuring requests_per_second.
The profile also includes 4 backoff/retry policies defined and response codes documented for throttled.
Tagged areas include Authentication, Authorization, Identity Management, and Rate Limiting.
Limits
Policies
Sources
Work with this as data
Every rate limit here is available over the APIs.io API and to AI agents over MCP.