[metadata]
algolia_content_type: Reference
algolia_product_filter: Cloudflare Fundamentals
description: Understand Cloudflare API rate limits, rate-limiting headers, and how to handle throttled requests.
generator: Astro v7.2.0
generator: Nimbus v0.2.2
image: https://developers.cloudflare.com/og-docs.png
og:description: Understand Cloudflare API rate limits, rate-limiting headers, and how to handle throttled requests.
og:image: https://developers.cloudflare.com/og-docs.png
og:locale: en
og:site_name: Cloudflare Docs
og:title: Rate limits
og:title: Rate limits · Cloudflare Fundamentals docs
og:type: article
og:url: https://developers.cloudflare.com/fundamentals/api/reference/limits/
pcx_additional_products: Cloudflare Fundamentals,API documentation
pcx_content_group: Core platform
pcx_content_type: Reference
pcx_last_modified: 116
pcx_product: Cloudflare Fundamentals
twitter:card: summary_large_image
twitter:image: https://developers.cloudflare.com/og-docs.png
twitter:site: @cloudflare
viewport: width=device-width, initial-scale=1

[canonical-links]
https://developers.cloudflare.com/fundamentals/api/reference/limits/

[document-links]
/
/cdn-cgi/ endpoint: /fundamentals/reference/cdn-cgi-endpoint/
AI Security: https://www.cloudflare.com/solutions/ai-security/
API deprecations: /fundamentals/api/reference/deprecations/
API token permissions: /fundamentals/api/reference/permissions/
API token template URLs: /fundamentals/api/how-to/account-owned-token-template/
API token templates: /fundamentals/api/reference/template/
API: /api/
About: https://www.cloudflare.com/about/
Account API tokens: /fundamentals/api/get-started/account-owned-tokens/
Account and domain management best practices: /fundamentals/reference/best-practices/
Account recovery: /fundamentals/user-profiles/account-recovery/
Accounts, zones, and profiles: /fundamentals/concepts/accounts-and-zones/
Add abuse contact: /fundamentals/account/account-security/abuse-contact/
Add multiple sites via automation: /fundamentals/manage-domains/add-multiple-sites-automation/
Agent setup ↗: /agent-setup/
Agent setup: /agent-setup/
Allow Cloudflare access: /fundamentals/account/account-security/cloudflare-access/
App innovation report: https://www.cloudflare.com/resource/app-innovation-report/
Athenian Project: https://www.cloudflare.com/athenian/
Audit Logs - v2: /fundamentals/account/account-security/audit-logs/
Authentik: /fundamentals/account/account-security/scim-setup/authentik/
Authorizing an application: /fundamentals/oauth/authorizing-an-application/
Available RSS Feeds: /fundamentals/new-features/available-rss-feeds/
Blocked Content: /fundamentals/reference/report-abuse/blocked-content/
Blog: https://blog.cloudflare.com/
Cache Purge APIs: /cache/how-to/purge-cache/#availability-and-limits
Careers: https://www.cloudflare.com/careers/
Case studies: https://www.cloudflare.com/case-studies/
Change Super Administrator: /fundamentals/account/change-super-admin/
Change your domain version: /fundamentals/manage-domains/domain-version/
Changelog: /changelog/
Cloudflare AI Cloud: https://www.cloudflare.com/solutions/ai/
Cloudflare Cookies: /fundamentals/reference/policies-compliances/cloudflare-cookies/
Cloudflare Docs llms-full.txt ↗: /llms-full.txt
Cloudflare Docs llms.txt ↗: /llms.txt
Cloudflare Fundamentals llms-full.txt ↗: /fundamentals/llms-full.txt
Cloudflare Fundamentals llms.txt ↗: /fundamentals/llms.txt
Cloudflare Fundamentals: /fundamentals/
Cloudflare HTTP headers: /fundamentals/reference/http-headers/
Cloudflare IP addresses: /fundamentals/concepts/cloudflare-ip-addresses/
Cloudflare Radar: https://radar.cloudflare.com/
Cloudflare Ray ID: /fundamentals/reference/cloudflare-ray-id/
Cloudflare Skills ↗: https://github.com/cloudflare/skills
Cloudflare and Google Analytics: /fundamentals/reference/google-analytics/
Cloudflare crawlers: /fundamentals/reference/cloudflare-site-crawling/
Cloudflare for Campaigns: https://www.cloudflare.com/campaigns/
Cloudflare's SDKs: /fundamentals/api/reference/sdks/
Cloudy AI agent Beta: /fundamentals/reference/cloudy-ai-agent/
Code Mode MCP Server ↗: https://github.com/cloudflare/mcp
Community: https://community.cloudflare.com/
Complaint types: /fundamentals/reference/report-abuse/complaint-types/
Compliance documentation: /fundamentals/reference/policies-compliances/compliance-docs/
Compliance resources: https://www.cloudflare.com/trust-hub/compliance-resources/
Connection limits: /fundamentals/reference/connection-limits/
Consuming RSS Feeds: /fundamentals/new-features/consuming-rss-feeds/
Contact sales: https://www.cloudflare.com/resource/contact-enterprise-sales/
Content Security Policies (CSPs): /fundamentals/reference/policies-compliances/content-security-policies/
Control API Access: /fundamentals/api/how-to/control-api-access/
Create API token: /fundamentals/api/get-started/create-token/
Create account: /fundamentals/account/create-account/
Create tokens via API: /fundamentals/api/how-to/create-via-api/
Create your OAuth client: /fundamentals/oauth/create-an-oauth-client/
Cryptographic Attestation of Personhood: /fundamentals/reference/cryptographic-personhood/
Customer abuse report obligations: /fundamentals/reference/report-abuse/abuse-report-obligations/
Data Protection: https://www.cloudflare.com/trust-hub/gdpr/
Delete your Cloudflare account: /fundamentals/user-profiles/delete-account/
Delivering Videos with Cloudflare: /fundamentals/reference/policies-compliances/delivering-videos-with-cloudflare/
Directory: /directory/
Docs: /
Documentation: https://developers.cloudflare.com/
Domain name search: https://domains.cloudflare.com/
Domain-specific MCP Servers ↗ MCP: https://github.com/cloudflare/mcp-server-cloudflare
Edit page: https://github.com/cloudflare/cloudflare-docs/edit/production/src/content/docs/fundamentals/api/reference/limits.mdx
Email address and password: /fundamentals/user-profiles/change-password-or-email/
Error responses: /fundamentals/reference/error-responses/
Events: https://www.cloudflare.com/events/
Find a partner: https://partnerlocator.cloudflare.com/dashboard
Find account and zone IDs: /fundamentals/account/find-account-and-zone-ids/
Frontend Development Platform: https://www.cloudflare.com/solutions/frontends/
Gateway Lists API: /cloudflare-one/reusable-components/lists/#api-rate-limit
Get Global API key (legacy): /fundamentals/api/get-started/keys/
Get Origin CA keys Deprecated: /fundamentals/api/get-started/ca-keys/
Get started: /fundamentals/get-started/
Global network: https://www.cloudflare.com/network/
Glossary: /fundamentals/reference/glossary/
GraphQL API ↗: /analytics/graphql-api/
GraphQL APIs: /analytics/graphql-api/limits/
Home: /
How Cloudflare DNS works: /fundamentals/concepts/how-cloudflare-works/
Impact/ESG: https://www.cloudflare.com/impact/
Improve SEO: /fundamentals/performance/improve-seo/
Integrate your OAuth client with Cloudflare: /fundamentals/oauth/integrate-with-cloudflare/
Investors: https://cloudflare.net/
Leaked Password Notifications: /fundamentals/account/account-security/leaked-password-notifications/
Learning center: https://www.cloudflare.com/learning/
Licenses: /fundamentals/reference/policies-compliances/licenses/
Limitations and troubleshooting: /fundamentals/organizations/limitations/
Lists API: /waf/tools/lists/lists-api/#rate-limiting-for-lists-api-requests
Log In: https://dash.cloudflare.com/login
Log in to Cloudflare: /fundamentals/user-profiles/login/
Log in: https://dash.cloudflare.com/
Maintenance mode: /fundamentals/performance/maintenance-mode/
Make API calls: /fundamentals/api/how-to/make-api-calls/
Manage active sessions: /fundamentals/account/account-security/manage-active-sessions/
Manage subdomains: /fundamentals/manage-domains/manage-subdomains/
Manage: /fundamentals/manage-members/manage/
Markdown for Agents Beta: /fundamentals/reference/markdown-for-agents/
Members and permissions: /fundamentals/manage-members/
Microsoft Entra: /fundamentals/account/account-security/scim-setup/entra/
Minimize downtime: /fundamentals/performance/minimize-downtime/
Move a domain between Cloudflare accounts: /fundamentals/manage-domains/move-domain/
Multi-Factor Email Authentication: /fundamentals/user-profiles/multi-factor-email-authentication/
Multi-Tenant Platform Development: https://www.cloudflare.com/solutions/platforms/
Network Layers: /fundamentals/reference/network-layers/
Network ports: /fundamentals/reference/network-ports/
Next SDKs: /fundamentals/api/reference/sdks/
Okta: /fundamentals/account/account-security/scim-setup/okta/
Onboard a domain: /fundamentals/manage-domains/add-site/
Optimize site speed ↗: /speed/
Organizations for Enterprise: /fundamentals/organizations/for-enterprise/
Organizations for MSSP and Distributors: /fundamentals/organizations/for-mssp-distributors/
Overview: /fundamentals/
Overview: /fundamentals/account/account-security/scim-setup/
Overview: /fundamentals/manage-domains/
Overview: /fundamentals/oauth/
Overview: /fundamentals/organizations/
Overview: /fundamentals/reference/report-abuse/
Overview: /fundamentals/user-profiles/
Partners: /fundamentals/reference/partners/
Partners: https://www.cloudflare.com/partners/
Pause Cloudflare: /fundamentals/manage-domains/pause-cloudflare/
Plans: https://www.cloudflare.com/plans/
Policies: /fundamentals/manage-members/policies/
Policy sharing: /fundamentals/organizations/policy-sharing/
Prepare for surges or spikes in web traffic ↗: /learning-paths/surge-readiness/concepts/
Press kit: https://www.cloudflare.com/press/press-kit/
Press: https://www.cloudflare.com/press/
Prevent DDoS attacks ↗: /learning-paths/prevent-ddos-attacks/concepts/
Previous API token templates: /fundamentals/api/reference/template/
Privacy policy: https://www.cloudflare.com/policies/privacy/
Profile settings: /fundamentals/user-profiles/customize-account/
Project Cybersafe Schools: /fundamentals/reference/policies-compliances/cybersafe/
Project Fairshot: https://www.cloudflare.com/fair-shot/
Project Galileo: https://www.cloudflare.com/galileo/
Protect your origin server: /fundamentals/security/protect-your-origin-server/
Providing specific URLs: /fundamentals/reference/report-abuse/provide-specific-urls/
REST API ↗ API: /api/
Rate limits: /fundamentals/api/reference/limits/
Recovering from a hacked site: /fundamentals/security/recovering-from-hacked-site/
Redirect one domain to another: /fundamentals/manage-domains/redirect-domain/
Redirects: /fundamentals/reference/redirects/
Remove a domain: /fundamentals/manage-domains/remove-domain/
Report abuse: https://www.cloudflare.com/trust-hub/abuse-approach/
Report issue: https://github.com/cloudflare/cloudflare-docs/issues/new/choose
Report security issues: https://www.cloudflare.com/disclosure/
Responsible AI: https://www.cloudflare.com/trust-hub/responsible-ai/
Restrict tokens: /fundamentals/api/how-to/restrict-tokens/
Review abuse policies: https://www.cloudflare.com/trust-hub/abuse-approach/
Review audit logs - v1: /fundamentals/account/account-security/review-audit-logs/
Role scopes: /fundamentals/manage-members/scope/
Roles: /fundamentals/manage-members/roles/
Roll tokens: /fundamentals/api/how-to/roll-token/
Rulesets APIs: /ruleset-engine/rulesets-api/#limits
SCIM migration: /fundamentals/reference/migration-guides/scim-virtual-groups-migration/
SDK ecosystem support policy: /fundamentals/reference/sdk-ecosystem-support-policy/
SDKs: /fundamentals/api/reference/sdks/
SSE and SASE platform: https://www.cloudflare.com/sase/
Scan for PCI compliance: /fundamentals/security/pci-scans/
Scans and penetration testing policy: /fundamentals/reference/scans-penetration/
Secure compromised account: /fundamentals/account/account-security/secure-a-compromised-account/
Secure your website ↗: /learning-paths/application-security/account-security/
Set up SSO ↗: /fundamentals/manage-members/dashboard-sso/
Set up dashboard SSO: /fundamentals/manage-members/dashboard-sso/
Star domains: /fundamentals/manage-domains/star-zones/
Start Building: https://dash.cloudflare.com/sign-up
Startups: https://www.cloudflare.com/startups/
Status: https://www.cloudflarestatus.com/
Support: https://support.cloudflare.com/
TCP connections: /fundamentals/reference/tcp-connections/
Terms of use: https://www.cloudflare.com/policies/terms/
Test speed: /fundamentals/performance/test-speed/
Token formats: /fundamentals/api/get-started/token-formats/
Trademark: https://www.cloudflare.com/trademark/
Traffic flow through Cloudflare: /fundamentals/concepts/traffic-flow-cloudflare/
Transparency report: https://www.cloudflare.com/transparency/
Troubleshooting: /fundamentals/account/account-security/scim-setup/troubleshooting/
Troubleshooting: /fundamentals/api/troubleshooting/
Troubleshooting: /fundamentals/reference/troubleshooting/
Trust Hub: https://www.cloudflare.com/trust-hub/
Two-factor authentication: /fundamentals/user-profiles/2fa/
Under Attack mode: /fundamentals/reference/under-attack-mode/
Under a DDoS attack?: /fundamentals/security/under-ddos-attack/
Under attack?: https://www.cloudflare.com/under-attack-hotline/
User Groups New: /fundamentals/manage-members/user-groups/
Verify email address: /fundamentals/user-profiles/verify-email-address/
View and submit reports: /fundamentals/reference/report-abuse/submit-report/
View as Markdown: index.md
Web Security Platform: https://www.cloudflare.com/solutions/security/
Wrangler API ↗: /workers/wrangler/api/
Zone holds: /fundamentals/account/account-security/zone-holds/
contact Cloudflare Support: /support/contacting-cloudflare-support/
https://github.com/cloudflare/cloudflare-docs

[structured-data]
{"@context":"https://schema.org","@id":"https://developers.cloudflare.com/fundamentals/api/reference/limits/#page","@type":"TechArticle","dateModified":"2026-04-20","description":"Understand Cloudflare API rate limits, rate-limiting headers, and how to handle throttled requests.","headline":"Rate limits · Cloudflare Fundamentals docs","image":"https://developers.cloudflare.com/og-docs.png","inLanguage":"en","isPartOf":{"@id":"https://developers.cloudflare.com/#website","@type":"WebSite","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"},"publisher":{"@type":"Organization","name":"Cloudflare","url":"https://www.cloudflare.com/"},"url":"https://developers.cloudflare.com/fundamentals/api/reference/limits/"}

[content]
Rate limits · Cloudflare Fundamentals docs
Skip to content
Documentation Index
Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt
Use this file to discover all available pages before exploring further.
Docs
Directory
API
SDKs
Changelog
Search
Ctrl
K
Log in
Cloudflare Fundamentals
/
Overview
Concepts
How Cloudflare DNS works
Traffic flow through Cloudflare
Accounts, zones, and profiles
Cloudflare IP addresses
Get started
Accounts
Create account
Account security
Add abuse contact
Allow Cloudflare access
Leaked Password Notifications
Manage active sessions
Review audit logs - v1
Audit Logs - v2
SCIM provisioning
Overview
Authentik
Microsoft Entra
Okta
Troubleshooting
Secure compromised account
Set up SSO ↗
Zone holds
Find account and zone IDs
Change Super Administrator
Organizations
Beta
Overview
Organizations for Enterprise
Organizations for MSSP and Distributors
Policy sharing
Limitations and troubleshooting
Members and permissions
Members and permissions
Manage
Policies
Roles
Role scopes
User Groups
New
Set up dashboard SSO
User profiles
Overview
Verify email address
Log in to Cloudflare
Profile settings
Account recovery
Delete your Cloudflare account
Email address and password
Multi-Factor Email Authentication
Two-factor authentication
Domains
Overview
Add multiple sites via automation
Change your domain version
Manage subdomains
Move a domain between Cloudflare accounts
Onboard a domain
Pause Cloudflare
Redirect one domain to another
Remove a domain
Star domains
Performance
Improve SEO
Maintenance mode
Minimize downtime
Optimize site speed ↗
Prepare for surges or spikes in web traffic ↗
Test speed
Security
Prevent DDoS attacks ↗
Protect your origin server
Recovering from a hacked site
Scan for PCI compliance
Secure your website ↗
Under a DDoS attack?
Cloudflare's API
Get started
Create API token
Get Global API key (legacy)
Get Origin CA keys
Deprecated
Token formats
Account API tokens
How to
Make API calls
Create tokens via API
Control API Access
Restrict tokens
Roll tokens
API token template URLs
Reference
REST API ↗
API
GraphQL API ↗
Wrangler API ↗
API token permissions
API deprecations
API token templates
Rate limits
SDKs
Troubleshooting
OAuth Applications on Cloudflare
Overview
Create your OAuth client
Integrate your OAuth client with Cloudflare
Authorizing an application
Reference
Migration guides
SCIM migration
Policies
Cloudflare Cookies
Compliance documentation
Content Security Policies (CSPs)
Delivering Videos with Cloudflare
Licenses
Project Cybersafe Schools
Abuse
Overview
Review abuse policies
Complaint types
Providing specific URLs
Customer abuse report obligations
View and submit reports
Blocked Content
SDK ecosystem support policy
Troubleshooting
/cdn-cgi/ endpoint
Account and domain management best practices
Cloudflare and Google Analytics
Cloudflare crawlers
Cloudflare HTTP headers
Cloudflare Ray ID
Cloudy AI agent
Beta
Connection limits
Cryptographic Attestation of Personhood
Error responses
Glossary
Markdown for Agents
Beta
Network Layers
Network ports
Partners
Redirects
Scans and penetration testing policy
TCP connections
Under Attack mode
RSS Feeds
Available RSS Feeds
Consuming RSS Feeds
Agent resources
Agent setup ↗
Cloudflare Skills ↗
Code Mode MCP Server ↗
Domain-specific MCP Servers ↗
MCP
Cloudflare Fundamentals llms.txt ↗
Cloudflare Fundamentals llms-full.txt ↗
Cloudflare Docs llms.txt ↗
Cloudflare Docs llms-full.txt ↗
Home
/
Cloudflare Fundamentals
/
…
Cloudflare's API
/
Reference
/
Rate limits
Rate limits
Last updated
Apr 20, 2026
|
Copy as Markdown
|
View as Markdown
|
Agent setup
Overview
API token limits
Rate limiting headers
API token limits
Type
Limit
Client API per user/account token
1200/5 minutes
Client API per IP
200/second
GraphQL
Varies by query cost. Max 320/5 min
User API token quota
50
Account API token quota
500
Note
The global rate limit for the Cloudflare API is 1,200 requests per five minute period per user, and applies cumulatively regardless of whether the request is made via the dashboard, API key, or API token.
If you exceed this limit, all API calls for the next five minutes will be blocked, receiving a
HTTP 429 - Too Many Requests
response.
Some specific API calls have their own limits and are documented separately, such as the following:
Cache Purge APIs
GraphQL APIs
Rulesets APIs
Lists API
Gateway Lists API
Enterprise customers can also
contact Cloudflare Support
to raise the Client API per user, GraphQL, or API token limits to a higher value.
Rate limiting headers
The following headers are returned when calling REST APIs:
Ratelimit
: List of service limit items, composed of the limit name, the remaining quota (
r
) and the time next window resets (
t
). For example:
"default";r=50;t=30
Ratelimit-Policy
: List of quota policy items, composed of the policy name, the total quota (
q
) and the time window the quota applies to (
w
). For example:
"burst";q=100;w=60
retry-after
: The number of seconds, rounded up, until more capacity is available. Note, this header is only returned when the request has exceeded the rate limit.
Cloudflare's SDKs
will also automatically work with the headers and back off in response to rate limits.
Previous
API token templates
Next
SDKs
Was this helpful?
Yes
No
Edit page
Report issue
On this page
Overview
API token limits
Rate limiting headers
Edit page
Report issue
Getting started
Plans
Contact sales
Partners
Find a partner
Startups
Under attack?
Domain name search
Company
About
Careers
Investors
Press
Press kit
Global network
Public interest
Project Galileo
Athenian Project
Cloudflare for Campaigns
Project Fairshot
Impact/ESG
Compliance
Compliance resources
Trust Hub
Data Protection
Responsible AI
Transparency report
Report abuse
Resources
App innovation report
Cloudflare Radar
Case studies
Status
Support
Events
Blog
Developers
Documentation
Learning center
Community
Solutions
SSE and SASE platform
Cloudflare AI Cloud
AI Security
Frontend Development Platform
Multi-Tenant Platform Development
Web Security Platform
Start Building
Log In
© 2026 Cloudflare, Inc.
Privacy policy
|
Report security issues
|
Terms of use
|
Trademark
|
Your privacy choices
Docs
