API and MCP Limits, Errors and Troubleshooting

Updated Oct 05, 2026

The request limits, the lookup budget and error codes of the REST API and the MCP server, and what to do when a request or an assistant is refused.

The REST API and the MCP server share your account's rules: the same domain limit, the same plan features and, for scans, domain tools and checks, the same budgets. This page lists the limits, every error code, and the usual fixes.

Limits

Limit Value Shared with
REST API requests 60 a minute per account
MCP requests 30 a minute (every message an assistant sends counts) per account
Check now 10 a minute the dashboard's Check now, the API and the MCP server
Lookups (scans and domain tools) Pro 300 a month, Business 1,500 a month, and 10 calls a minute API and MCP combined
Names per batch request 100
Domains you can monitor your plan's limit everything

Scans and the domain tools spend lookups. Most calls cost one; a few read many names and cost more:

Call Lookups
Scan, availability, WHOIS, expiry, age, SSL, DNS, email deliverability, punycode 1
DNS propagation 2
Typosquat check, name ideas 5
Bulk check 1 per name

A call that costs more than you have left is refused whole, and nothing is spent. A tool that finds nothing (success: false) has still read the registry, so it still costs. The budget resets on the 1st of each month; unused lookups do not carry over.

The lookup budget is separate from the dashboard's scan page. You can watch both under Settings → Subscription → Plan usage, and GET /me (or the assistant's whoami tool) shows lookups.remaining and lookups.resets_at.

When a limit is reached, the API answers 429 with a Retry-After header giving the seconds to wait. An assistant receives a short message such as "Too many checks requested. Try again shortly." and will usually tell you.

Error codes (REST API)

Every error has the same shape:

{ "error": { "code": "not_found", "message": "…", "details": {} } }

Switch on code; message is written for people and may change.

Code Status Meaning What to do
unauthenticated 401 No token, or it is expired or revoked Check the Authorization: Bearer header; create a new token if it expired
plan_required 403 Your plan does not include the API, or this feature See plans and limits
insufficient_scope 403 The token lacks the scope this endpoint needs details.required names it; create a token with that scope
limit_reached 403 Your domain limit leaves no room for any of the names Remove domains or upgrade
forbidden 403 The action is not allowed Read message
not_found 404 No such endpoint, or a domain you do not monitor Check the full name, e.g. example.co.uk; batch requests list the names in details.domains
method_not_allowed 405 Wrong HTTP method for this endpoint See the API reference
validation_failed 422 A field is missing or invalid details maps each field to its errors
refused 422 A write was not applied in full details.written and details.skipped count the rows; message says why
throttled 429 Too many requests, or the lookup budget is spent Wait for Retry-After
bad_request 4xx The request could not be processed Check the body is valid JSON
server_error 5xx Something went wrong on our side Retry later; contact support if it persists

Troubleshooting the API

Every request answers 401. The header must be exactly Authorization: Bearer <token>, with no quotes around the token. If it worked before, the token may have expired or been revoked; the token list in Settings → API & MCP shows both.

It worked yesterday and now answers plan_required. The account's plan changed. Your tokens are kept; upgrading makes them work again.

A domain I can see in the dashboard answers 404. Use the full name including its extension (example.co.uk, not example), and check it is in this account rather than a teammate's.

POST /domains answered 200 but some names were not added. Adding is per name: look at the failed list. already_monitoring means the name is already in your account.

Troubleshooting an AI assistant

The assistant cannot connect, or the approval page only offers Cancel. The MCP server needs the Pro or Business plan.

The assistant says a tool is not available, or "Tool not found". The connection was approved without the permission that tool needs. Disconnect the app under Settings → API & MCP → Connected apps and connect again, approving the permission.

The assistant says "You do not monitor example.com." It only sees domains in your account. Ask it to add the name first, or to scan it instead.

The assistant asks you to sign in again. Access lapses after 30 days without use, or when you disconnect it. Approve it again from the assistant.

The assistant will not change or remove a domain. That is deliberate: assistants can read and add, not change or delete. See what it cannot do.

More in API and AI Assistants

Related guides and tutorials.

View all