The REST API and the MCP server share your account's rules: the same domain limit, the same plan features and, for scans, domain tools and checks, the same budgets. This page lists the limits, every error code, and the usual fixes.
Limits
| Limit | Value | Shared with |
|---|---|---|
| REST API requests | 60 a minute | per account |
| MCP requests | 30 a minute (every message an assistant sends counts) | per account |
| Check now | 10 a minute | the dashboard's Check now, the API and the MCP server |
| Lookups (scans and domain tools) | Pro 300 a month, Business 1,500 a month, and 10 calls a minute | API and MCP combined |
| Names per batch request | 100 | |
| Domains you can monitor | your plan's limit | everything |
Scans and the domain tools spend lookups. Most calls cost one; a few read many names and cost more:
| Call | Lookups |
|---|---|
| Scan, availability, WHOIS, expiry, age, SSL, DNS, email deliverability, punycode | 1 |
| DNS propagation | 2 |
| Typosquat check, name ideas | 5 |
| Bulk check | 1 per name |
A call that costs more than you have left is refused whole, and nothing is spent. A tool that finds nothing (success: false) has still read the registry, so it still costs. The budget resets on the 1st of each month; unused lookups do not carry over.
The lookup budget is separate from the dashboard's scan page. You can watch both under Settings → Subscription → Plan usage, and GET /me (or the assistant's whoami tool) shows lookups.remaining and lookups.resets_at.
When a limit is reached, the API answers 429 with a Retry-After header giving the seconds to wait. An assistant receives a short message such as "Too many checks requested. Try again shortly." and will usually tell you.
Error codes (REST API)
Every error has the same shape:
{ "error": { "code": "not_found", "message": "…", "details": {} } }
Switch on code; message is written for people and may change.
| Code | Status | Meaning | What to do |
|---|---|---|---|
unauthenticated |
401 | No token, or it is expired or revoked | Check the Authorization: Bearer header; create a new token if it expired |
plan_required |
403 | Your plan does not include the API, or this feature | See plans and limits |
insufficient_scope |
403 | The token lacks the scope this endpoint needs | details.required names it; create a token with that scope |
limit_reached |
403 | Your domain limit leaves no room for any of the names | Remove domains or upgrade |
forbidden |
403 | The action is not allowed | Read message |
not_found |
404 | No such endpoint, or a domain you do not monitor | Check the full name, e.g. example.co.uk; batch requests list the names in details.domains |
method_not_allowed |
405 | Wrong HTTP method for this endpoint | See the API reference |
validation_failed |
422 | A field is missing or invalid | details maps each field to its errors |
refused |
422 | A write was not applied in full | details.written and details.skipped count the rows; message says why |
throttled |
429 | Too many requests, or the lookup budget is spent | Wait for Retry-After |
bad_request |
4xx | The request could not be processed | Check the body is valid JSON |
server_error |
5xx | Something went wrong on our side | Retry later; contact support if it persists |
Troubleshooting the API
Every request answers 401. The header must be exactly Authorization: Bearer <token>, with no quotes around the token. If it worked before, the token may have expired or been revoked; the token list in Settings → API & MCP shows both.
It worked yesterday and now answers plan_required. The account's plan changed. Your tokens are kept; upgrading makes them work again.
A domain I can see in the dashboard answers 404. Use the full name including its extension (example.co.uk, not example), and check it is in this account rather than a teammate's.
POST /domains answered 200 but some names were not added. Adding is per name: look at the failed list. already_monitoring means the name is already in your account.
Troubleshooting an AI assistant
The assistant cannot connect, or the approval page only offers Cancel. The MCP server needs the Pro or Business plan.
The assistant says a tool is not available, or "Tool not found". The connection was approved without the permission that tool needs. Disconnect the app under Settings → API & MCP → Connected apps and connect again, approving the permission.
The assistant says "You do not monitor example.com." It only sees domains in your account. Ask it to add the name first, or to scan it instead.
The assistant asks you to sign in again. Access lapses after 30 days without use, or when you disconnect it. Approve it again from the assistant.
The assistant will not change or remove a domain. That is deliberate: assistants can read and add, not change or delete. See what it cannot do.