Constructs a RateLimitBinding instance.
Optionalsettings: RateLimitSettings
Resolved settings. Defaults to resolve('rateLimit'), so
callers normally construct this with no arguments at all.
Private ReadonlyfailWhether an unbound limiter admits the request.
Private ReadonlysettingsThis accessor’s settings, resolved on first read.
The binding name this instance resolves.
The binding name as declared in wrangler.json.
Checks whether the binding is available on the given environment.
Use this to degrade gracefully when a binding is optional.
The Worker environment.
true when the binding is present.
Counts one request against a key and reports whether it is within the rate.
The Worker environment.
What to count against — an IP, a user id, a route name.
true when the request is within the rate, false when it is
over. Returns RateLimitBinding.failOpen when the binding is
absent.
The key decides what is being limited, and choosing it is the whole design: a client IP limits one caller, a conversation id limits one conversation, a route name limits everyone at once. Cloudflare hashes it, so it may carry an identifier — but it is still a key in a shared namespace, so prefix it when one binding limits more than one thing.
Calling this is the increment. There is no way to ask without counting, which means a request must be checked exactly once.
Resolves the binding, failing fast when it is not configured.
The Worker environment.
The resolved binding.
MissingBindingError When the binding is absent from the environment.
Resolves the binding without throwing.
The Worker environment.
The resolved binding, or null when it is not configured.
Accessor for a rate limiting binding (
ratelimitsinwrangler.json).Remarks
Unlike every other binding here, the interesting configuration is not in
src/config/and cannot be: the rate and the window are fixed inwrangler.jsonat deploy time, and the runtime API takes only the key to count against. A Worker that needs two different rates declares two bindings and constructs one of these per binding.The limiter is eventually consistent and scoped to a Cloudflare location, so the effective global rate is higher than the configured one — by roughly the number of locations seeing traffic. It is an abuse control, not an accounting record: never use it for anything that must balance, like a quota a customer is billed against.
Example
Author
Bayu Dwiyan Satria
Version
1.0.0
Since
1.0.0