Rate Limiting Configuration¶
Set Escape's request rate to match your application's capacity and rate limits.
Configuration¶
Adjust the scan rate using the requests_per_second parameter in the network section:
Default Behavior¶
The schema default is 100 requests per second, with a range of 1 to 1000. Profiles created in the UI start at 500 requests per second. Adjust the Rate limit slider (10 to 500) under Fine-Tune > Duration during profile creation, or set network.requests_per_second in the expert YAML configuration.
This setting limits API DAST requests and ASM HTTP requests and probes. It doesn't throttle browser navigation.
Best Practices¶
- Start with default settings
- Gradually reduce rate if encountering API limits
- Monitor scan duration and coverage
- Prioritize scan accuracy over speed
Performance Tuning
The optimal rate depends on your specific API's capacity and performance characteristics. Begin with default settings and adjust incrementally.
Reference
Detailed configuration options are available in the configuration references: