Rate Limits
Rate limits are applied per API key, per rolling window. The limits depend on your subscription plan.
Limits by plan
| Plan | Lookups / month | Lookups / min | Reporting | Blocklists |
|---|---|---|---|---|
| Free | 1,000 | 10 | 50 / month | Daily refresh |
| Pro | 50,000 | 60 | Unlimited | Hourly refresh |
| Business | 500,000 | 300 | Unlimited | Real-time |
| Enterprise | Custom | Custom | Unlimited | Real-time + SLA |
Response headers
Every response includes rate-limit metadata so you can track consumption:
| Header | Description |
|---|---|
| X-RateLimit-Limit | Max requests in the current window |
| X-RateLimit-Remaining | Requests left in the current window |
| X-RateLimit-Reset | Unix timestamp when the window resets |
| Retry-After | Seconds to wait (only present on 429 responses) |
Handling 429 Too Many Requests
When you exceed the per-minute limit the API returns HTTP 429. Use the Retry-After header to wait the correct amount of time:
TypeScript
async function lookupWithRetry(ip: string, retries = 3): Promise<Response> {
const res = await fetch(`https://api.ipabuse.org/v1/ip/${ip}/reputation`, {
headers: { "X-API-Key": process.env.IPABUSE_API_KEY! },
});
if (res.status === 429 && retries > 0) {
const retryAfter = Number(res.headers.get("Retry-After") ?? 1);
await new Promise((r) => setTimeout(r, retryAfter * 1000));
return lookupWithRetry(ip, retries - 1);
}
return res;
}Burst allowance
All plans include a short burst allowance of up to 2× the per-minute limit for up to 5 seconds. Sustained traffic above your plan limit will be throttled.
Need more?
Upgrade your plan at ipabuse.org/billing or contact us for a custom Enterprise quote.
Next steps
- Error Reference — all error codes explained.
- Webhooks — get notified instead of polling.