Rate limits
How Project Zero's limits appear to an API client.
Project Zero is limited by the shared daily Zero Pool, which resets at 00:00 UTC. When it cannot serve, a request is refused with 503 zero_capacity_unavailable and a reset_at time.
Per-developer allocations and concurrency controls may apply. Their thresholds are not a published contract and are not documented here — read the code and reset_at in the refusal rather than assuming a number.
Client behaviour
- Do not retry a 503 zero_capacity_unavailable in a tight loop; wait for reset_at.
- Check GET /v1/zero/status before a batch of work to see whether Project Zero can serve.