[metadata]
description: Learn about REST API rate limits, how to avoid exceeding them, and what to do if you do exceed them.
google-site-verification: c1kuD-K2HIVF635lypcsWPoD4kilo5-jA_wBFyT4uMY
og:image: https://docs.github.com/assets/cb-345/images/social-cards/rest.png
og:site_name: GitHub Docs
og:title: Rate limits for the REST API - GitHub Enterprise Server 3.21 Docs
og:type: article
og:url: https://docs-internal.github.com/en/enterprise-server@3.21/rest/using-the-rest-api/rate-limits-for-the-rest-api
page-document-type: article
path-article: rest/using-the-rest-api/rate-limits-for-the-rest-api
path-language: en
path-product: rest
path-version: enterprise-server@3.21
status: 200
twitter:card: summary
twitter:description: Learn about REST API rate limits, how to avoid exceeding them, and what to do if you do exceed them.
twitter:domain: docs-internal.github.com
twitter:image: https://docs.github.com/assets/cb-345/images/social-cards/rest.png
twitter:title: Rate limits for the REST API - GitHub Enterprise Server 3.21 Docs
twitter:url: https://docs-internal.github.com/en/enterprise-server@3.21/rest/using-the-rest-api/rate-limits-for-the-rest-api
viewport: width=device-width, initial-scale=1

[document-links]
API Versions: /en/enterprise-server@3.21/rest/about-the-rest-api/api-versions
About the REST API: /en/enterprise-server@3.21/rest/about-the-rest-api/about-the-rest-api
Admin stats: /en/enterprise-server@3.21/rest/enterprise-admin/admin-stats
Alert dismissal requests: /en/enterprise-server@3.21/rest/code-scanning/alert-dismissal-requests
Alert dismissal requests: /en/enterprise-server@3.21/rest/dependabot/alert-dismissal-requests
Alert dismissal requests: /en/enterprise-server@3.21/rest/secret-scanning/alert-dismissal-requests
Alerts: /en/enterprise-server@3.21/rest/dependabot/alerts
Announcement: /en/enterprise-server@3.21/rest/enterprise-admin/announcement
Artifacts: /en/enterprise-server@3.21/rest/actions/artifacts
Ask the GitHub community: https://github.com/orgs/community/discussions
Assignees: /en/enterprise-server@3.21/rest/issues/assignees
Audit log: /en/enterprise-server@3.21/rest/enterprise-admin/audit-log
Authenticating: /en/enterprise-server@3.21/rest/authentication/authenticating-to-the-rest-api
Autolinks: /en/enterprise-server@3.21/rest/repos/autolinks
Best practices: /en/enterprise-server@3.21/rest/using-the-rest-api/best-practices-for-using-the-rest-api
Billing: /en/enterprise-server@3.21/rest/billing/billing
Blobs: /en/enterprise-server@3.21/rest/git/blobs
Blog: https://github.blog
Branches: /en/enterprise-server@3.21/rest/branches/branches
Breaking changes: /en/enterprise-server@3.21/rest/about-the-rest-api/breaking-changes
Building a CI server: /en/enterprise-server@3.21/rest/guides/building-a-ci-server
Bypass requests: /en/enterprise-server@3.21/rest/enterprise-admin/bypass-requests
Bypass requests: /en/enterprise-server@3.21/rest/orgs/bypass-requests
Bypass requests: /en/enterprise-server@3.21/rest/repos/bypass-requests
CORS and JSONP: /en/enterprise-server@3.21/rest/using-the-rest-api/using-cors-and-jsonp-to-make-cross-origin-requests
Cache: /en/enterprise-server@3.21/rest/actions/cache
Check runs: /en/enterprise-server@3.21/rest/checks/runs
Check suites: /en/enterprise-server@3.21/rest/checks/suites
Code scanning: /en/enterprise-server@3.21/rest/code-scanning/code-scanning
Codes of conduct: /en/enterprise-server@3.21/rest/codes-of-conduct/codes-of-conduct
Collaborators: /en/enterprise-server@3.21/rest/collaborators/collaborators
Comments: /en/enterprise-server@3.21/rest/gists/comments
Comments: /en/enterprise-server@3.21/rest/issues/comments
Commit comments: /en/enterprise-server@3.21/rest/commits/comments
Commit statuses: /en/enterprise-server@3.21/rest/commits/statuses
Commits: /en/enterprise-server@3.21/rest/commits/commits
Commits: /en/enterprise-server@3.21/rest/git/commits
Comparing GitHub's APIs: /en/enterprise-server@3.21/rest/about-the-rest-api/comparing-githubs-rest-api-and-graphql-api
Configurations: /en/enterprise-server@3.21/rest/code-security/configurations
Configuring rate limits: /en/enterprise-server@3.21/admin/configuring-settings/configuring-user-applications-for-your-enterprise/configuring-rate-limits
Contact support: https://support.github.com
Contents: /en/enterprise-server@3.21/rest/repos/contents
Custom properties for organizations: /en/enterprise-server@3.21/rest/enterprise-admin/custom-properties-for-orgs
Custom properties for organizations: /en/enterprise-server@3.21/rest/orgs/custom-properties-for-orgs
Custom properties: /en/enterprise-server@3.21/rest/enterprise-admin/custom-properties
Custom properties: /en/enterprise-server@3.21/rest/orgs/custom-properties
Custom properties: /en/enterprise-server@3.21/rest/repos/custom-properties
Custom roles: /en/enterprise-server@3.21/rest/orgs/custom-roles
Delivering deployments: /en/enterprise-server@3.21/rest/guides/delivering-deployments
Dependency review: /en/enterprise-server@3.21/rest/dependency-graph/dependency-review
Dependency submission: /en/enterprise-server@3.21/rest/dependency-graph/dependency-submission
Deploy keys: /en/enterprise-server@3.21/rest/deploy-keys/deploy-keys
Deployment branch policies: /en/enterprise-server@3.21/rest/deployments/branch-policies
Deployment statuses: /en/enterprise-server@3.21/rest/deployments/statuses
Deployments: /en/enterprise-server@3.21/rest/deployments/deployments
Discover resources for a user: /en/enterprise-server@3.21/rest/guides/discovering-resources-for-a-user
Draft Project items: /en/enterprise-server@3.21/rest/projects/drafts
Emails: /en/enterprise-server@3.21/rest/users/emails
Emojis: /en/enterprise-server@3.21/rest/emojis/emojis
Encrypt secrets: /en/enterprise-server@3.21/rest/guides/encrypting-secrets-for-the-rest-api
Endpoints for GitHub App installation tokens: /en/enterprise-server@3.21/rest/authentication/endpoints-available-for-github-app-installation-access-tokens
Endpoints for GitHub App user tokens: /en/enterprise-server@3.21/rest/authentication/endpoints-available-for-github-app-user-access-tokens
Endpoints for fine-grained PATs: /en/enterprise-server@3.21/rest/authentication/endpoints-available-for-fine-grained-personal-access-tokens
Enterprise team members: /en/enterprise-server@3.21/rest/enterprise-teams/enterprise-team-members
Enterprise team organizations: /en/enterprise-server@3.21/rest/enterprise-teams/enterprise-team-organizations
Enterprise teams: /en/enterprise-server@3.21/rest/enterprise-teams/enterprise-teams
Environments: /en/enterprise-server@3.21/rest/deployments/environments
Events: /en/enterprise-server@3.21/rest/activity/events
Events: /en/enterprise-server@3.21/rest/issues/events
Expert services: https://services.github.com
External groups: /en/enterprise-server@3.21/rest/teams/external-groups
Feeds: /en/enterprise-server@3.21/rest/activity/feeds
Followers: /en/enterprise-server@3.21/rest/users/followers
Forks: /en/enterprise-server@3.21/rest/repos/forks
GPG keys: /en/enterprise-server@3.21/rest/users/gpg-keys
Get started - Checks: /en/enterprise-server@3.21/rest/guides/using-the-rest-api-to-interact-with-checks
Get started - Git database: /en/enterprise-server@3.21/rest/guides/using-the-rest-api-to-interact-with-your-git-database
Getting started: /en/enterprise-server@3.21/rest/using-the-rest-api/getting-started-with-the-rest-api
Gists: /en/enterprise-server@3.21/rest/gists/gists
Git LFS: /en/enterprise-server@3.21/rest/repos/lfs
Git SSH keys: /en/enterprise-server@3.21/rest/users/keys
GitHub App installations: /en/enterprise-server@3.21/rest/enterprise-admin/organization-installations
GitHub Apps: /en/enterprise-server@3.21/rest/apps/apps
GitHub Docs: /en/enterprise-server@3.21
GitHub event types: /en/enterprise-server@3.21/rest/using-the-rest-api/github-event-types
Gitignore: /en/enterprise-server@3.21/rest/gitignore/gitignore
Global security advisories: /en/enterprise-server@3.21/rest/security-advisories/global-advisories
Global webhooks: /en/enterprise-server@3.21/rest/enterprise-admin/global-webhooks
Home: /en/enterprise-server@3.21
Installations: /en/enterprise-server@3.21/rest/apps/installations
Invitations: /en/enterprise-server@3.21/rest/collaborators/invitations
Issue dependencies: /en/enterprise-server@3.21/rest/issues/issue-dependencies
Issue event types: /en/enterprise-server@3.21/rest/using-the-rest-api/issue-event-types
Issue field values: /en/enterprise-server@3.21/rest/issues/issue-field-values
Issues: /en/enterprise-server@3.21/rest/issues/issues
Keeping API credentials secure: /en/enterprise-server@3.21/rest/authentication/keeping-your-api-credentials-secure
LDAP: /en/enterprise-server@3.21/rest/enterprise-admin/ldap
Labels: /en/enterprise-server@3.21/rest/issues/labels
Learn how to contribute: /contributing
Libraries: /en/enterprise-server@3.21/rest/using-the-rest-api/libraries-for-the-rest-api
Licenses: /en/enterprise-server@3.21/rest/licenses/licenses
Licensing: /en/enterprise-server@3.21/rest/enterprise-admin/licensing
Make a contribution: https://github.com/github/docs/blob/main/content/rest/using-the-rest-api/rate-limits-for-the-rest-api.md
Manage GHES: /en/enterprise-server@3.21/rest/enterprise-admin/manage-ghes
Markdown: /en/enterprise-server@3.21/rest/markdown/markdown
Members: /en/enterprise-server@3.21/rest/orgs/members
Members: /en/enterprise-server@3.21/rest/teams/members
Meta: /en/enterprise-server@3.21/rest/meta/meta
Milestones: /en/enterprise-server@3.21/rest/issues/milestones
Notifications: /en/enterprise-server@3.21/rest/activity/notifications
OAuth app authorizations: /en/enterprise-server@3.21/rest/oauth-authorizations/oauth-authorizations
OAuth authorizations: /en/enterprise-server@3.21/rest/apps/oauth-applications
OIDC: /en/enterprise-server@3.21/rest/actions/oidc
OpenAPI description: /en/enterprise-server@3.21/rest/about-the-rest-api/about-the-openapi-description-for-the-rest-api
Organization configurations: /en/enterprise-server@3.21/rest/private-registries/organization-configurations
Organization pre-receive hooks: /en/enterprise-server@3.21/rest/enterprise-admin/org-pre-receive-hooks
Organization roles: /en/enterprise-server@3.21/rest/orgs/organization-roles
Organization: /en/enterprise-server@3.21/rest/announcement-banners/organizations
Organizations: /en/enterprise-server@3.21/rest/enterprise-admin/orgs
Organizations: /en/enterprise-server@3.21/rest/migrations/orgs
Organizations: /en/enterprise-server@3.21/rest/orgs/orgs
Outside collaborators: /en/enterprise-server@3.21/rest/orgs/outside-collaborators
Packages: /en/enterprise-server@3.21/rest/packages/packages
Pages: /en/enterprise-server@3.21/rest/pages/pages
Pagination: /en/enterprise-server@3.21/rest/using-the-rest-api/using-pagination-in-the-rest-api
Permissions for GitHub Apps: /en/enterprise-server@3.21/rest/authentication/permissions-required-for-github-apps
Permissions for fine-grained PATs: /en/enterprise-server@3.21/rest/authentication/permissions-required-for-fine-grained-personal-access-tokens
Permissions: /en/enterprise-server@3.21/rest/actions/permissions
Personal access tokens: /en/enterprise-server@3.21/rest/orgs/personal-access-tokens
Pre-receive environments: /en/enterprise-server@3.21/rest/enterprise-admin/pre-receive-environments
Pre-receive hooks: /en/enterprise-server@3.21/rest/enterprise-admin/pre-receive-hooks
Pricing: https://github.com/pricing
Privacy policy: /en/site-policy/privacy-policies/github-privacy-statement
Privacy: /en/site-policy/privacy-policies/github-privacy-statement
Project fields: /en/enterprise-server@3.21/rest/projects/fields
Project items: /en/enterprise-server@3.21/rest/projects/items
Project views: /en/enterprise-server@3.21/rest/projects/views
Projects: /en/enterprise-server@3.21/rest/projects/projects
Protected branches: /en/enterprise-server@3.21/rest/branches/branch-protection
Protection rules: /en/enterprise-server@3.21/rest/deployments/protection-rules
Pull requests: /en/enterprise-server@3.21/rest/pulls/pulls
Push protection bypass: /en/enterprise-server@3.21/rest/secret-scanning/delegated-bypass
Push protection: /en/enterprise-server@3.21/rest/secret-scanning/push-protection
Quickstart: /en/enterprise-server@3.21/rest/quickstart
REST API: /en/enterprise-server@3.21/rest
REST API: /en/rest
Rate limit: /en/enterprise-server@3.21/rest/rate-limit/rate-limit
Rate limits for the REST API: /en/rest/using-the-rest-api/rate-limits-for-the-rest-api
Rate limits: /en/enterprise-server@3.21/rest/using-the-rest-api/rate-limits-for-the-rest-api
Reactions: /en/enterprise-server@3.21/rest/reactions/reactions
References: /en/enterprise-server@3.21/rest/git/refs
Release assets: /en/enterprise-server@3.21/rest/releases/assets
Releases: /en/enterprise-server@3.21/rest/releases/releases
Rendering data as graphs: /en/enterprise-server@3.21/rest/guides/rendering-data-as-graphs
Repositories: /en/enterprise-server@3.21/rest/repos/repos
Repository access: /en/enterprise-server@3.21/rest/dependabot/repository-access
Repository pre-receive hooks: /en/enterprise-server@3.21/rest/enterprise-admin/repo-pre-receive-hooks
Review comments: /en/enterprise-server@3.21/rest/pulls/comments
Review requests: /en/enterprise-server@3.21/rest/pulls/review-requests
Reviews: /en/enterprise-server@3.21/rest/pulls/reviews
Rule suites: /en/enterprise-server@3.21/rest/orgs/rule-suites
Rule suites: /en/enterprise-server@3.21/rest/repos/rule-suites
Rules: /en/enterprise-server@3.21/rest/enterprise-admin/rules
Rules: /en/enterprise-server@3.21/rest/orgs/rules
Rules: /en/enterprise-server@3.21/rest/repos/rules
SCIM: /en/enterprise-server@3.21/rest/enterprise-admin/scim
SSH signing keys: /en/enterprise-server@3.21/rest/users/ssh-signing-keys
Script with JavaScript: /en/enterprise-server@3.21/rest/guides/scripting-with-the-rest-api-and-javascript
Script with Ruby: /en/enterprise-server@3.21/rest/guides/scripting-with-the-rest-api-and-ruby
Search: /en/enterprise-server@3.21/rest/search/search
Secret scanning: /en/enterprise-server@3.21/rest/secret-scanning/secret-scanning
Secrets: /en/enterprise-server@3.21/rest/actions/secrets
Secrets: /en/enterprise-server@3.21/rest/dependabot/secrets
Security features for code: /en/enterprise-server@3.21/rest/enterprise-admin/code-security-and-analysis
Security managers: /en/enterprise-server@3.21/rest/orgs/security-managers
Self-hosted runner groups: /en/enterprise-server@3.21/rest/actions/self-hosted-runner-groups
Self-hosted runners: /en/enterprise-server@3.21/rest/actions/self-hosted-runners
Social accounts: /en/enterprise-server@3.21/rest/users/social-accounts
Software bill of materials (SBOM): /en/enterprise-server@3.21/rest/dependency-graph/sboms
Starring: /en/enterprise-server@3.21/rest/activity/starring
Statistics: /en/enterprise-server@3.21/rest/metrics/statistics
Status: https://www.githubstatus.com/
Tags: /en/enterprise-server@3.21/rest/git/tags
Teams: /en/enterprise-server@3.21/rest/teams/teams
Terms: /en/site-policy/github-terms/github-terms-of-service
Timeline: /en/enterprise-server@3.21/rest/issues/timeline
Timezones: /en/enterprise-server@3.21/rest/using-the-rest-api/timezones-and-the-rest-api
Trees: /en/enterprise-server@3.21/rest/git/trees
Troubleshooting: /en/enterprise-server@3.21/rest/using-the-rest-api/troubleshooting-the-rest-api
Users: /en/enterprise-server@3.21/rest/enterprise-admin/users
Users: /en/enterprise-server@3.21/rest/migrations/users
Users: /en/enterprise-server@3.21/rest/users/users
Using the REST API: /en/enterprise-server@3.21/rest/using-the-rest-api
Variables: /en/enterprise-server@3.21/rest/actions/variables
Watching: /en/enterprise-server@3.21/rest/activity/watching
Webhooks: /en/enterprise-server@3.21/rest/apps/webhooks
Webhooks: /en/enterprise-server@3.21/rest/orgs/webhooks
Webhooks: /en/enterprise-server@3.21/rest/repos/webhooks
Workflow jobs: /en/enterprise-server@3.21/rest/actions/workflow-jobs
Workflow runs: /en/enterprise-server@3.21/rest/actions/workflow-runs
Workflows: /en/enterprise-server@3.21/rest/actions/workflows
Working with comments: /en/enterprise-server@3.21/rest/guides/working-with-comments

[content]
Rate limits for the REST API - GitHub Enterprise Server 3.21 Docs
Skip to main content
GitHub Docs
Version:
Enterprise Server 3.21
Search or ask Copilot
Search or ask
Copilot
Select language: current language is English
Search or ask Copilot
Search or ask
Copilot
Open menu
Collapse sidebar
Expand sidebar
Scroll breadcrumbs left
Home
REST API
Using the REST API
Rate limits
Scroll breadcrumbs right
REST API
API Version:
2026-03-10 (latest)
Quickstart
About the REST API
About the REST API
Comparing GitHub's APIs
API Versions
Breaking changes
OpenAPI description
Using the REST API
Getting started
Rate limits
Pagination
Libraries
Best practices
Troubleshooting
Timezones
CORS and JSONP
Issue event types
GitHub event types
Authentication
Authenticating
Keeping API credentials secure
Endpoints for GitHub App installation tokens
Endpoints for GitHub App user tokens
Endpoints for fine-grained PATs
Permissions for GitHub Apps
Permissions for fine-grained PATs
Guides
Script with JavaScript
Script with Ruby
Discover resources for a user
Delivering deployments
Rendering data as graphs
Working with comments
Building a CI server
Get started - Git database
Get started - Checks
Encrypt secrets
Actions
Artifacts
Cache
OIDC
Permissions
Secrets
Self-hosted runner groups
Self-hosted runners
Variables
Workflow jobs
Workflow runs
Workflows
Activity
Events
Feeds
Notifications
Starring
Watching
Announcement banners
Organization
Apps
GitHub Apps
Installations
OAuth authorizations
Webhooks
Billing
Billing
Branches
Branches
Protected branches
Checks
Check runs
Check suites
Code scanning
Alert dismissal requests
Code scanning
Code security settings
Configurations
Codes of conduct
Codes of conduct
Collaborators
Collaborators
Invitations
Commits
Commits
Commit comments
Commit statuses
Dependabot
Alert dismissal requests
Alerts
Repository access
Secrets
Dependency graph
Dependency review
Dependency submission
Software bill of materials (SBOM)
Deploy keys
Deploy keys
Deployments
Deployment branch policies
Deployments
Environments
Protection rules
Deployment statuses
Emojis
Emojis
Enterprise administration
Admin stats
Announcement
Audit log
Bypass requests
Security features for code
Custom properties
Custom properties for organizations
Global webhooks
LDAP
Licensing
Manage GHES
Organization pre-receive hooks
GitHub App installations
Organizations
Pre-receive environments
Pre-receive hooks
Repository pre-receive hooks
Rules
SCIM
Users
Enterprise teams
Enterprise team members
Enterprise team organizations
Enterprise teams
Gists
Gists
Comments
Git database
Blobs
Commits
References
Tags
Trees
Gitignore
Gitignore
Issues
Assignees
Comments
Events
Issue dependencies
Issue field values
Issues
Labels
Milestones
Timeline
Licenses
Licenses
Markdown
Markdown
Meta
Meta
Metrics
Statistics
Migrations
Organizations
Users
OAuth app authorizations
OAuth app authorizations
Organizations
Bypass requests
Custom properties
Custom properties for organizations
Custom roles
Members
Organization roles
Organizations
Outside collaborators
Personal access tokens
Rule suites
Rules
Security managers
Webhooks
Packages
Packages
Pages
Pages
Private registries
Organization configurations
Projects
Draft Project items
Project fields
Project items
Projects
Project views
Pull requests
Review comments
Pull requests
Review requests
Reviews
Rate limit
Rate limit
Reactions
Reactions
Releases
Releases
Release assets
Repositories
Autolinks
Bypass requests
Contents
Custom properties
Forks
Git LFS
Repositories
Rule suites
Rules
Webhooks
Search
Search
Secret scanning
Alert dismissal requests
Push protection bypass
Push protection
Secret scanning
Security advisories
Global security advisories
Teams
External groups
Members
Teams
Users
Emails
Followers
GPG keys
Git SSH keys
Social accounts
SSH signing keys
Users
Rate limits for the REST API
Learn about REST API rate limits, how to avoid exceeding them, and what to do if you do exceed them.
Copy as Markdown
Rate limits are disabled by default for GitHub Enterprise Server. Contact your site administrator to confirm the rate limits for your instance.
If you are a site administrator, you can set rate limits, including secondary rate limits, for your instance. See
Configuring rate limits
.
If you are developing an app for users or organizations outside of your instance, the standard GitHub rate limits apply. See
Rate limits for the REST API
in the GitHub Free documentation.
About secondary rate limits
In addition to primary rate limits, GitHub enforces secondary rate limits in order to prevent abuse and keep the API available for all users.
You may encounter a secondary rate limit if you:
Make too many concurrent requests.
No more than 100 concurrent requests are allowed. This limit is shared across the REST API and GraphQL API.
Make too many requests to a single endpoint per minute.
No more than 900 points per minute are allowed for REST API endpoints, and no more than 2,000 points per minute are allowed for the GraphQL API endpoint. For more information about points, see
Calculating points for the secondary rate limit
.
Make too many requests per minute.
No more than 90 seconds of CPU time per 60 seconds of real time is allowed. No more than 60 seconds of this CPU time may be for the GraphQL API. You can roughly estimate the CPU time by measuring the total response time for your API requests.
Make too many requests that consume excessive compute resources in a short period of time.
Create too much content on GitHub in a short amount of time.
In general, no more than 80 content-generating requests per minute and no more than 500 content-generating requests per hour are allowed. Some endpoints have lower content creation limits. Content creation limits include actions taken on the GitHub web interface as well as via the REST API and GraphQL API.
Make too many OAuth access token requests in a short period of time.
No more than 2,000 OAuth access token requests per hour are allowed for GitHub Apps and OAuth apps.
These secondary rate limits are subject to change without notice. You may also encounter a secondary rate limit for undisclosed reasons.
Calculating points for the secondary rate limit
Some secondary rate limits are determined by the point values of requests. For GraphQL requests, these point values are separate from the point value calculations for the primary rate limit.
Request
Points
GraphQL requests without mutations
1
GraphQL requests with mutations
5
Most REST API
GET
,
HEAD
, and
OPTIONS
requests
1
Most REST API
POST
,
PATCH
,
PUT
, or
DELETE
requests
5
Some REST API endpoints have a different point cost that is not shared publicly.
Help and support
Did you find what you needed?
Yes
No
Privacy policy
Help us make these docs great!
All GitHub docs are open source. See something that's wrong or unclear? Submit a pull request.
Make a contribution
Learn how to contribute
Still need help?
Ask the GitHub community
Contact support
Legal
©
2026
GitHub, Inc.
Terms
Privacy
Status
Pricing
Expert services
Blog
