## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Docs update
## What is the current behavior?
The Auth rate-limit table contains stale customization statuses and time
windows, omits SMS and Web3 limits, and describes the anonymous sign-in
burst incorrectly.
## What is the new behavior?
- Aligns documented limits with the current Auth, Studio, and Management
API behavior
- Documents SMS, Web3, and sign-up/sign-in request limits
- Corrects verification, token, MFA, email, and anonymous sign-in
details
- Updates shared rate-limit values and units used by the docs
## Additional context
Validation:
- Prettier check
- Focused MDX lint
- Shared-data TypeScript check
- All 16 SharedData references resolve
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Updates**
* Refined authentication rate limits with clearer per-minute and
per-five-minute windows.
* Added rate limits for SMS, password reset requests, and Web3 sign-ups
and sign-ins.
* Updated sign-in, sign-up, verification, token refresh, MFA, and
anonymous sign-in limits, including customizable settings where
supported.
* Clarified email-sending limits and OTP behavior.
* **Documentation**
* Updated rate-limit reference tables and guidance on request bucket
capacity and sustained traffic.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
* fix: remove warning on branching that services are not available
* fix: convert branching duration to constant
* fix: add callout related to pg_cron and inactivity related pausing