Rate Limit Policies
Define multi-tier rate-limit policies scoped per key, app, or customer, with soft or hard enforcement modes and optional burst capacity — read by your API gateway at the edge.
Rate Limit Policies
Rate Limit Policies (Settings → Rate Limit Policies) define the throttle configuration your API gateway reads at the edge. Each policy targets a scope and stacks one or more time-window tiers. Aforo stores and resolves the policy; the gateway (Kong, or your ingestion plugin) applies it on the request path.
Policy scope & enforcement
Tiers
A policy stacks multiple windows — for example 100 requests/minute and 5,000 requests/hour:
Add tiers with + Add Tier in the create/edit drawer. The KPI strip shows total policies and the split between hard and soft enforcement.
Aforo resolves each policy and publishes it to a cache the gateway reads; the gateway is what actually rejects or flags over-limit traffic (a HARD policy typically maps to an HTTP 429 at the gateway). Define policies here, and enforce them at whichever gateway fronts your API. Native in-product enforcement is on the roadmap.