Sign in →

Rate Limit Policies

Define multi-tier rate-limit policies scoped per key, app, or customer, with soft or hard enforcement modes and optional burst capacity — read by your API gateway at the edge.

Updated 2026-07-29Suggest edits

Rate Limit Policies

Rate Limit Policies (Settings → Rate Limit Policies) define the throttle configuration your API gateway reads at the edge. Each policy targets a scope and stacks one or more time-window tiers. Aforo stores and resolves the policy; the gateway (Kong, or your ingestion plugin) applies it on the request path.

Policy scope & enforcement

FieldValues
ScopePER_KEY, PER_APP, PER_CUSTOMER
Enforcement modeHARD (gateway rejects over-limit requests) or SOFT (gateway allows but flags them) — the mode is a directive the gateway acts on

Tiers

A policy stacks multiple windows — for example 100 requests/minute and 5,000 requests/hour:

Tier fieldNotes
Window60s (1 min) or 3600s (1 hour) — resolution currently honors per-minute and per-hour windows
Max requestsCap within the window
Burst capacityOptional short-term allowance
PriorityOptional ordering

Add tiers with + Add Tier in the create/edit drawer. The KPI strip shows total policies and the split between hard and soft enforcement.

ℹ

Aforo resolves each policy and publishes it to a cache the gateway reads; the gateway is what actually rejects or flags over-limit traffic (a HARD policy typically maps to an HTTP 429 at the gateway). Define policies here, and enforce them at whichever gateway fronts your API. Native in-product enforcement is on the roadmap.