Cloud
Rate Limiting
Per-tenant sliding window rate limiter with configurable rules.
Overview
The rate limiter enforces per-tenant request limits using a sliding window counter. Each tenant can have its own rate limit, and standard rate-limit headers are set automatically on every response.
Usage
typescript
Response Headers
Every response includes standard rate-limit headers:
| Header | Description |
|---|---|
X-RateLimit-Limit | Maximum requests in the window |
X-RateLimit-Remaining | Requests remaining in the window |
X-RateLimit-Reset | Unix timestamp when the window resets |
X-RateLimit-Tenant | The tenant ID the limit applies to |
Exceeding the Limit
When a tenant exceeds their limit, the middleware returns:
- HTTP 429 Too Many Requests
- JSON body with
retryAfterMsindicating when to retry
Custom Key Extraction
Override how rate-limit keys are generated:
typescript
Bypassing System Paths
Exclude health checks and metrics endpoints from rate limiting to prevent dashboards from being throttled during heavy load testing.
typescript
Options Reference
| Option | Type | Default | Description |
|---|---|---|---|
defaultRule | { max, windowMs } | — | Fallback rate limit |
tenantRules | Record<string, { max, windowMs }> | {} | Per-tenant overrides |
keyExtractor | (req) => string | tenant:method:path | Custom key function |