Skip to content
ZeroCaptcha

Limits

Every limit the API applies, in one place. Values marked “by default” are the service’s settings, which can change: the RateLimit-Policy header and each task’s own fields (deadline, maxAttempts, tokenExpiresAt) always say what applies to you.

Limit Value
Request body 64 KiB by default; larger is payload_too_large (413)
Server time per request 10 seconds by default; longer is request_timeout (504)
Idempotency-Key 1 to 255 visible ASCII characters; kept for 24 hours
Tasks per list page 1 to 100; 50 by default
Field Limit
websiteURL http or https, at most 2,048 characters, no credentials, the scheme’s default port, a public domain name
websiteKey 1 to 100 letters, digits, _ and -
action Up to 32 letters, digits, _ and -
cdata Up to 255 letters, digits, _ and -
proxy http or https with a port; a public host; not a port another protocol reserves; login and password at most 255 bytes each; host name at most 253 characters
callbackUrl http or https, at most 2,048 characters, no credentials, a public domain or IP address, not a port another protocol reserves
Limit Value
Deadline 150 seconds after creation by default (the task’s deadline)
Solve attempts 3 by default (the task’s maxAttempts); none started with under 5 seconds left
Tasks queued or running per account 50 by default, beyond which queue_full (429, Retry-After: 2)
Tasks queued across the service 5,000, beyond which queue_full
Creation rate No budget by default: your balance and queue share bound it
Turnstile token Valid once, for 300 seconds from tokenIssuedAt
Challenge clearance Served for 30 minutes from tokenIssuedAt; the site’s own setting decides how long it accepts it
Tokens and clearances deleted 10 minutes after they expire
Proxy credentials deleted When the task finishes
Task records kept About 90 days: deleted a month at a time, once their month ended more than 90 days ago
Budget Value
Reads per key 200 every 2 seconds by default
Reads per account 200 every 2 seconds by default, all keys together
Live-update streams per account 10 at once by default
GET /v1/prices and GET /v1/status 60 a minute per client address by default

Over a budget: rate_limited (429) with Retry-After; ERROR_RATE_LIMIT in the createTask format; ERROR: 1005 in 2Captcha’s.

Limit Value
Active API keys per account 20; a key being replaced by a rotation, and a revoked key, do not count
Allowed addresses per key 100 IP addresses or CIDR networks
Rotation overlap 1 hour, 24 hours or 7 days
Daily spend cap Any amount in whole cents, per key, per UTC day; none by default
Open team invitations 20 per account; each link works once, for 7 days
Passkeys 20 per person
Recovery codes 10, each once
Dashboard session 24 hours idle, 30 days at most
Recent sign-in, for sensitive changes 10 minutes
Password At least 8 characters
Limit Value
Smallest top-up $10
Largest top-up No maximum
Amounts US dollars; top-ups in whole cents, balances and prices to six decimals
Refunds None: top-ups are final
Limit Value
Time to answer 10 seconds per attempt
Attempts 8, from 30 seconds apart doubling to 32 minutes apart, each wait lengthened by up to half at random
Signature tolerance 5 minutes between t and your clock