API Documentation

Limits and Timeouts

Rate limits, request lifetimes, long-polls and sizes.

Documentation Pages

The Numbers

LimitValue
All calls per integration (both APIs together)600 per 60 seconds
New push requests per user email10 per 10 minutes
Requests waiting for an answer per user3
Push request lifetime in the Auth API60 seconds
Request lifetime in the simple API (ttlSeconds)30 to 300 seconds, default 60
Pause after Not me (per user and integration)15 minutes
Backup code checks per user5 per 5 minutes
The backup code locks after10 wrong tries in a row
Long-poll of auth_statusup to 8 seconds
Long-poll of GET /v1/integrations/requests (wait)0 to 25 seconds
An auth call without async waitsup to 62 seconds
Waits open at the same time per integration20; beyond that auth_status answers at once, and auth without async answers 42901
Date header distance from the server clockat most 5 minutes
Request body size128 KiB
pushinfounder 20000 bytes
Request title (type, title) and context values120 characters, the rest is cut
Activation code of enrolldefault 1 day, 60 seconds to 7 days
Result of an async passcode or a refused pushreadable for 5 minutes

Advice

  • Use an HTTP timeout above 65 seconds for auth without async, and above 10 seconds for auth_status.
  • On 429, wait as long as the Retry-After header says. Duo's official libraries already retry with growing pauses.
  • Do not call preauth and auth many times for one sign-in attempt. One push per attempt is enough and keeps users from being flooded.
  • These limits never loosen when their storage is unavailable: requests are refused instead (429).

Duo is a trademark of Cisco. WiraPass is not affiliated with Duo or Cisco and only offers API compatibility.