Counts one request against a key and says whether to serve it.
The Worker environment.
What to count against — a client IP, a user id, a route name. Prefix it when one binding limits more than one thing, since the namespace is shared.
true when the request should be served, false when the caller
is over its allowance and the route should answer 429.
Reports whether a limiter is bound to this Worker.
The Worker environment.
true when the binding is present.
Rate limiting capability, backed by Cloudflare's rate limiting binding.
Remarks
What this is for is the endpoint that cannot be addressed by an API key — a browser-facing route, or anything named in
excludedRoutes— where there is no caller identity to hold accountable and the only lever left is how often one client may knock. The origin allowlist inSecurityMiddlewaresays who may call; this says how often.Enforcement is per Cloudflare location and eventually consistent, so treat the configured rate as a floor rather than a ceiling. That imprecision is fine for shedding abuse and wrong for anything a customer is billed against.
By default the limiter is optional infrastructure: with no binding declared, every request is admitted. Override
rateLimit.failOpentofalsewhere an absent limiter would leave something genuinely exposed.Example
Author
Bayu Dwiyan Satria
Version
1.0.0
Since
1.0.0