Default quotas per API instance are 120 requests/minute for an anonymous IP bucket, 180 for a signed-in user and 300 per application. Operators can configure them.
All keys and machine OAuth clients for one application share its quota. Issuing another key does not increase it. HTTP 429 includes Retry-After.
The current limiter is process-local, not distributed. Before scaling to multiple replicas, configure a shared edge or Redis quota. No paid plans or SLA are offered.