Authentication/End-user rate limits
This page provides the API rate limits for authentication and end-user activities, which is part of Okta rate limits.
- To learn more about rate limits, visit our overview and best practices pages.
- In addition to the rate limit per API, Okta implements limits on concurrent requests, Okta-generated email messages, end user requests, and home page endpoints. These limits are described on the Additional limits page.
- You can expand Okta rate limits upon request. To learn how, see Request exceptions and DynamicScale rate limits.
We enforce limits at the individual API endpoint level as requests per minute.
|Action and Okta API Endpoint||Developer (free)||Developer (paid)||One App||Enterprise||Workforce Identity|
|Cumulative rate limit||1,700||9,000||9,000||11,200||13,900|
|Authenticate different end users: ||100||600||600||600||500|
|Verify a factor: ||100||600||600||600||500|
|Get session information: ||100||600||600||600||750|
|OAuth2 requests for Custom Authorization Servers: ||300||1,200||1,200||1,200||2,000|
|OAuth2 requests for the Org Authorization Server: ||300||1,200||1,200||1,200||2,000|
|All other OAuth2 requests: ||100||600||600||600||600|
Note: The following public metadata endpoints aren't subjected to rate limiting.
Public metadata endpoints for the Org Authorization Server are:
Public metadata endpoints for the Custom Authorization Servers are: