Documentation Pages
The Numbers
| Limit | Value |
| All calls per integration (both APIs together) | 600 per 60 seconds |
| New push requests per user email | 10 per 10 minutes |
| Requests waiting for an answer per user | 3 |
| Push request lifetime in the Auth API | 60 seconds |
| Request lifetime in the simple API (ttlSeconds) | 30 to 300 seconds, default 60 |
| Pause after Not me (per user and integration) | 15 minutes |
| Backup code checks per user | 5 per 5 minutes |
| The backup code locks after | 10 wrong tries in a row |
| Long-poll of auth_status | up to 8 seconds |
| Long-poll of GET /v1/integrations/requests (wait) | 0 to 25 seconds |
| An auth call without async waits | up to 62 seconds |
| Waits open at the same time per integration | 20; beyond that auth_status answers at once, and auth without async answers 42901 |
| Date header distance from the server clock | at most 5 minutes |
| Request body size | 128 KiB |
| pushinfo | under 20000 bytes |
| Request title (type, title) and context values | 120 characters, the rest is cut |
| Activation code of enroll | default 1 day, 60 seconds to 7 days |
| Result of an async passcode or a refused push | readable for 5 minutes |
Advice
- Use an HTTP timeout above 65 seconds for auth without async, and above 10 seconds for auth_status.
- On 429, wait as long as the Retry-After header says. Duo's official libraries already retry with growing pauses.
- Do not call preauth and auth many times for one sign-in attempt. One push per attempt is enough and keeps users from being flooded.
- These limits never loosen when their storage is unavailable: requests are refused instead (429).