Cloudflare - v1.3.0
    Preparing search index...

    Class RateLimitBinding<E>

    Accessor for a rate limiting binding (ratelimits in wrangler.json).

    Unlike every other binding here, the interesting configuration is not in src/config/ and cannot be: the rate and the window are fixed in wrangler.json at deploy time, and the runtime API takes only the key to count against. A Worker that needs two different rates declares two bindings and constructs one of these per binding.

    The limiter is eventually consistent and scoped to a Cloudflare location, so the effective global rate is higher than the configured one — by roughly the number of locations seeing traffic. It is an abuse control, not an accounting record: never use it for anything that must balance, like a quota a customer is billed against.

    const limiter = new RateLimitBinding() // binding name from the configuration layer
    const { success } = await limiter.limit(ctx.env, ip)

    Bayu Dwiyan Satria

    1.0.0

    1.0.0

    Type Parameters

    Hierarchy (View Summary)

    Index
    failOpen: boolean

    Whether an unbound limiter admits the request.

    settings: () => RateLimitSettings

    This accessor’s settings, resolved on first read.

    • get name(): string

      The binding name this instance resolves.

      Returns string

      The binding name as declared in wrangler.json.

    • Checks whether the binding is available on the given environment.

      Use this to degrade gracefully when a binding is optional.

      Parameters

      • env: E

        The Worker environment.

      Returns boolean

      true when the binding is present.

    • Counts one request against a key and reports whether it is within the rate.

      Parameters

      • env: E

        The Worker environment.

      • key: string

        What to count against — an IP, a user id, a route name.

      Returns Promise<boolean>

      true when the request is within the rate, false when it is over. Returns RateLimitBinding.failOpen when the binding is absent.

      The key decides what is being limited, and choosing it is the whole design: a client IP limits one caller, a conversation id limits one conversation, a route name limits everyone at once. Cloudflare hashes it, so it may carry an identifier — but it is still a key in a shared namespace, so prefix it when one binding limits more than one thing.

      Calling this is the increment. There is no way to ask without counting, which means a request must be checked exactly once.

    • Resolves the binding without throwing.

      Parameters

      • env: E

        The Worker environment.

      Returns RateLimit

      The resolved binding, or null when it is not configured.