Rate limits
Request limits, cooldowns, and quota.
Three layers of rate limiting apply to every embed request. The first two refuse the request outright. The third, the org quota, only blocks work that needs a fresh scan, so an over-quota org can still be served from cache on the routes that check the cache first.
IP limit
7 requests per minute per IP, over a rolling 60 second window. It applies to embed requests, meaning requests carrying a ?key= that resolved to an org.
Returns 429 with RATE_LIMITED.
Address cooldown
20 seconds between requests for the same address per org. Prevents hammering the same target.
Token map scans check their cache first, so a cached token result is served without waiting out the cooldown. Wallet scans, funding chains, and cross-chain traces apply the cooldown before the cache lookup, so a repeat request for the same wallet inside 20 seconds is refused even when the answer was cached.
Returns 429 with EMBED_MINT_COOLDOWN.
Org usage limits
Your org has daily and monthly request caps set during onboarding. Every embed request counts against them, cached or fresh. A cached result is free in the sense that it runs no new scan, but it still spends one unit of the daily and monthly allowance.
Returns 429 with EMBED_QUOTA_EXCEEDED when exceeded.
Adjustments go through your Telegram channel, or email payments@scanner.net.
Error examples
{ "error": "Too many requests", "code": "RATE_LIMITED" }{ "error": "Scan cooldown: 18s remaining", "code": "EMBED_MINT_COOLDOWN" }{ "error": "Embed quota exceeded", "code": "EMBED_QUOTA_EXCEEDED" }Caching
Scans are cached for 1 hour with up to 3 versions per token and scan mode. Within that window, requests return cached data instantly. After the cache expires, the next request runs a fresh scan.
Checking your usage
Contact us for current stats, or request admin dashboard access to see real-time numbers: daily/monthly usage vs limits, top mints, top domains.