Skip to content

Rate Limiting Configuration

Set Escape's request rate to match your application's capacity and rate limits.

Configuration

Adjust the scan rate using the requests_per_second parameter in the network section:

network:
  requests_per_second: 50 # Schema default is 100; UI-created profiles start at 500

Default Behavior

The schema default is 100 requests per second, with a range of 1 to 1000. Profiles created in the UI start at 500 requests per second. Adjust the Rate limit slider (10 to 500) under Fine-Tune > Duration during profile creation, or set network.requests_per_second in the expert YAML configuration.

This setting limits API DAST requests and ASM HTTP requests and probes. It doesn't throttle browser navigation.

Best Practices

  • Start with default settings
  • Gradually reduce rate if encountering API limits
  • Monitor scan duration and coverage
  • Prioritize scan accuracy over speed

Performance Tuning

The optimal rate depends on your specific API's capacity and performance characteristics. Begin with default settings and adjust incrementally.

Reference

Detailed configuration options are available in the configuration references: