Creating secrets through the API, the CLI or a CI job used to stop after 10 in 10 minutes, which cut off any setup script that declared more than that. The limit is now 100 every 10 minutes, enough to create every secret a project can hold in a single run.
Counted per project
The limit used to be counted per IP address. That meant two jobs on the same CI provider could share one allowance, and a busy office could use up yours. It is now counted per project: everyone working on a project, with any API key and from any machine, shares the same 100, and nobody else's traffic counts against it.
Nothing else about secrets changes. How many a project can hold is still set
by its plan and the secrets packs it has bought, and going over that still
returns a 402.
See Usage Limits in the secrets guide.