Limits and Enforcement
Last updated: 2026-10-03 Version: 1.4 Status: Advance notice Effective: New products and features: first use on or after 7 October 2026; existing services: 10 November 2026, subject to the notice period below
For newly available products and features, this edition applies when you first choose to use the relevant service and accept its terms, on or after 7 October 2026. The product must actually be launched and available to you. For changes to services you already use, this edition applies from 10 November 2026, but never earlier than 30 days after we notify you of the changes, or a later date required by applicable law. Until then, the previous conditions continue for those existing services. Accepting in advance does not shorten that transition. Publication and acceptance do not make a product available or establish regulatory permission.
This policy explains access limits and enforcement for the Service operated by Supa Labs OÜ, registry code 17399414. It accompanies the Terms, AUP and API Terms. Contact: legal@swaps.app.
1. Different kinds of limits
Request budgets protect infrastructure. Product amount limits, account eligibility, verification, available balance, provider caps and country restrictions independently determine whether an instruction can proceed. Passing a request limit does not authorise a transaction.
Quotas can be shared by account, observed IP address, client or operation class. Creating extra keys does not necessarily create another budget. Users sharing a network or proxy can share an observed-IP limit. Do not rotate identities or credentials to evade a budget.
2. Public API request budgets
The following standard configured budgets apply to the relevant enabled public API routes at this version; additional route, network or security controls can apply.
| Class | Budget per minute | Scope |
|---|---|---|
| Pre-authentication | 300 for the observed IP and 300 for the observed IP/credential combination | Both checks apply |
| Authenticated reads | 600 | Account |
| Authenticated non-money writes | 120 | Account |
| Authenticated money-boundary operations | 30 | Account |
| Public-token reads | 60 | Observed IP |
| Public short-link resolution | 10 | Observed IP |
| Public-token non-money writes | 20 | Observed IP |
| Public-token money operations | 10 | Observed IP |
A rate-limited request returns 429 with retry guidance. Where the API's distributed limiter cannot safely make a decision, it can return 503 instead of accepting an instruction. Do not treat either response as proof about a previously submitted transaction; reconcile an uncertain operation before retrying.
3. Other surfaces
Legacy agent endpoints apply plan budgets separately from the public API operation classes above:
| Plan | Per minute | Per day |
|---|---|---|
| Free | 10 | 500 |
| Pro | 60 | 10,000 |
| Enterprise | 300 | 1,000,000 |
Those plan figures are not a statement that the same per-day budgets apply to every public API route. MCP discovery and tool calls can have additional transport or tool budgets.
Payment Links' direct public actions use separate observed-IP budgets: reads/status 60/minute, rail selection 10/minute, receipt email 15/minute, and "I've sent it" confirmation 10/minute. These differ from the public API class table. Rail selection can be unavailable when its limiter is unavailable; some read or corrective-write surfaces use local fallback throttling during an outage.
Web quote, Address Check, authentication and other endpoints can have their own controls. A listed table is not a guarantee of sustained throughput or an exhaustive description of anti-abuse detection.
3.1 Address Check free-check allowance
Each registered user receives one free full-report check in total as a one-time introductory allowance for Address Check across all supported access points, including Ask Swaps. This is a shared allowance per user, not a separate allowance per product name, device, session, workspace or API key, and it does not renew monthly. Creating additional accounts must not be used to repeat the allowance.
Previously used introductory checks count toward this allowance when this edition becomes applicable to you; the change does not grant a fresh allowance. The existing-service transition and notice period at the start of this policy apply. Checks that were free when performed are not charged retrospectively. Purchased Credits and separately earned referral Credits are not reduced by this change.
Brief previews and cached re-reads of an existing full report are distinct from generating a new full report. Request budgets in the tables above are not free-report entitlements. Further full reports use available Credits under the Address Check Terms, with the applicable charge shown before generation.
4. Amount and provider restrictions
The relevant product and confirmation screen show supported amount, asset, network, rail and verification conditions. Provider caps may be lower than a platform cap and may depend on funding source, residence, account type or cumulative activity. Do not split a payment or use a different identity to avoid a condition.
We may tighten access temporarily for an incident, abuse or provider requirement. Material changes to a purchased entitlement are handled under the Terms and mandatory law; a technical policy does not permit undisclosed retroactive charges.
5. Enforcement measures
Depending on the evidence and risk, we may throttle requests, request more information, restrict a feature, disable a webhook, revoke a key, deactivate a payment link or suspend or terminate an account. We consider seriousness, impact, recurrence, accuracy of information and applicable obligations.
Automation can impose an immediate restriction without prior human review. A restriction or risk signal is not a conclusive allegation of wrongdoing. Where lawful and reasonably practicable, we explain the reason and what can resolve it. Notice may be delayed for urgent security needs or a legal restriction.
We do not promise that every control is identical on every surface. A provider may independently restrict its service. Revoking a credential does not cancel an instruction already accepted by a provider or reverse a blockchain transaction.
6. Review, funds and rights
For a disputed measure, contact legal@swaps.app with the account or request reference, the issue and correcting information. Do not send secrets. We will assess the request, explain the outcome where lawful, and identify a separate provider process when appropriate.
Paid entitlements and pending funds are addressed under the product terms and applicable law. A breach does not automatically make every balance non-refundable or give Swaps ownership of an accidental deposit. An interface restriction does not grant power to freeze a self-controlled wallet.
You retain applicable complaint, consumer and data-protection rights. A privacy request does not automatically suspend a necessary security control, but we must still assess that request under the Privacy Policy.