Every limit the API applies, in one place. Values marked “by default” are the service’s settings,
which can change: the RateLimit-Policy header and each task’s own fields (deadline,
maxAttempts, tokenExpiresAt) always say what applies to you.
| Limit |
Value |
| Request body |
64 KiB by default; larger is payload_too_large (413) |
| Server time per request |
10 seconds by default; longer is request_timeout (504) |
Idempotency-Key |
1 to 255 visible ASCII characters; kept for 24 hours |
| Tasks per list page |
1 to 100; 50 by default |
| Field |
Limit |
websiteURL |
http or https, at most 2,048 characters, no credentials, the scheme’s default port, a public domain name |
websiteKey |
1 to 100 letters, digits, _ and - |
action |
Up to 32 letters, digits, _ and - |
cdata |
Up to 255 letters, digits, _ and - |
proxy |
http or https with a port; a public host; not a port another protocol reserves; login and password at most 255 bytes each; host name at most 253 characters |
callbackUrl |
http or https, at most 2,048 characters, no credentials, a public domain or IP address, not a port another protocol reserves |
| Limit |
Value |
| Deadline |
150 seconds after creation by default (the task’s deadline) |
| Solve attempts |
3 by default (the task’s maxAttempts); none started with under 5 seconds left |
| Tasks queued or running per account |
50 by default, beyond which queue_full (429, Retry-After: 2) |
| Tasks queued across the service |
5,000, beyond which queue_full |
| Creation rate |
No budget by default: your balance and queue share bound it |
| Turnstile token |
Valid once, for 300 seconds from tokenIssuedAt |
| Challenge clearance |
Served for 30 minutes from tokenIssuedAt; the site’s own setting decides how long it accepts it |
| Tokens and clearances deleted |
10 minutes after they expire |
| Proxy credentials deleted |
When the task finishes |
| Task records kept |
About 90 days: deleted a month at a time, once their month ended more than 90 days ago |
| Budget |
Value |
| Reads per key |
200 every 2 seconds by default |
| Reads per account |
200 every 2 seconds by default, all keys together |
| Live-update streams per account |
10 at once by default |
GET /v1/prices and GET /v1/status |
60 a minute per client address by default |
Over a budget: rate_limited (429) with Retry-After;
ERROR_RATE_LIMIT in the createTask format; ERROR: 1005 in 2Captcha’s.
| Limit |
Value |
| Active API keys per account |
20; a key being replaced by a rotation, and a revoked key, do not count |
| Allowed addresses per key |
100 IP addresses or CIDR networks |
| Rotation overlap |
1 hour, 24 hours or 7 days |
| Daily spend cap |
Any amount in whole cents, per key, per UTC day; none by default |
| Open team invitations |
20 per account; each link works once, for 7 days |
| Passkeys |
20 per person |
| Recovery codes |
10, each once |
| Dashboard session |
24 hours idle, 30 days at most |
| Recent sign-in, for sensitive changes |
10 minutes |
| Password |
At least 8 characters |
| Limit |
Value |
| Smallest top-up |
$10 |
| Largest top-up |
No maximum |
| Amounts |
US dollars; top-ups in whole cents, balances and prices to six decimals |
| Refunds |
None: top-ups are final |
| Limit |
Value |
| Time to answer |
10 seconds per attempt |
| Attempts |
8, from 30 seconds apart doubling to 32 minutes apart, each wait lengthened by up to half at random |
| Signature tolerance |
5 minutes between t and your clock |