All skills
upstash avatar

/upstash-ratelimit-js

@36daab8
by upstashupstash/skills27 stars
7

Rate limiting for serverless and edge apps with the @upstash/ratelimit TypeScript/JavaScript SDK backed by Upstash Redis. Use when adding a rate limiter or throttling to an API route, Next.js middleware, Vercel Edge, Cloudflare Workers, or any HTTP endpoint; returning 429 Too Many Requests; choosing between fixed window, sliding window, and token bucket algorithms; limiting per user, IP, API key, or tenant with prefixes and custom keys; protecting login, signup, form, or AI endpoints from abuse, bots, and brute force; using deny lists, ephemeral caching, analytics, timeouts, and multi-region rate limits; or estimating the Redis command cost of rate limiting. Also use when the user says rate limit, rate-limiting, throttle, quota, request limits, or traffic protection.

Use this Skill: https://skilld.dev/gh/upstash/skills/upstash-ratelimit-js

This session only. Nothing lands on disk.

algorithms.md

≈684 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Ratelimiting Algorithms

This documentation explains the three algorithms supported by the ratelimit‑ts SDK: Fixed Window, Sliding Window, and Token Bucket. It focuses on practical usage, pitfalls, and choosing the right algorithm.

Fixed Window

Divides time into fixed periods (for example, 10‑second windows). Requests increment a counter for the current window and are rejected once the limit is exceeded.

Pitfalls

  • Burst leakage: many requests at the boundary may bypass intended behavior.
  • Stampedes: large client populations may all retry at the start of a window.
  • Reset time is based on fixed boundaries, not on the first request.

When to use

  • When performance and low computational cost are important.
  • When small inaccuracies at boundaries are acceptable.

Example

// 10 requests per 10 seconds
const regional = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.fixedWindow(10, "10 s"),
});

const multi = new MultiRegionRatelimit({
  redis: [new Redis({/* auth */}), new Redis({/* auth */})],
  limiter: MultiRegionRatelimit.fixedWindow(10, "10 s"),
});

Sliding Window

Uses rolling time windows to smooth boundary behavior. Counts requests in the previous window proportionally based on elapsed time.

Pitfalls

  • Slightly more expensive to compute and approximate.
  • Assumes uniform distribution of past requests.
  • In multi‑region mode, generates many Redis commands and can slow down operations.
  • Reset time exposed via limit and getRemaining is only the start of the next full window.

When to use

  • When smoother behavior around window boundaries is important.
  • Avoid in multi‑region setups if command count is a concern.

Example

// 10 requests per 10 seconds
const regional = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.slidingWindow(10, "10 s"),
});

// Multi-region is possible but inefficient
const multi = new MultiRegionRatelimit({
  redis: [new Redis({/* auth */}), new Redis({/* auth */})],
  limiter: MultiRegionRatelimit.slidingWindow(10, "10 s"),
});

Token Bucket

Maintains a bucket of tokens that refill at a defined rate. Each request consumes one token; if none remain, requests are rejected.

Advantages

  • Smooths bursts naturally.
  • Allows high initial burst capacity (maxTokens > refillRate).

Pitfalls

  • Higher computational cost.
  • Not yet supported for multi‑region.

When to use

  • When smoothing request traffic and allowing controlled bursts is important.

Example

// Bucket with max 10 tokens, refilling 5 tokens every 10s
const ratelimit = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.tokenBucket(5, "10 s", 10),
  analytics: true,
});

Source: SKILL.md on GitHub

No alerts17d3 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides comprehensive documentation and implementation examples for the Upstash Rate Limit SDK. It adheres to security best practices, such as recommending environment variables for credential management and using official vendor packages.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

Signed by skilld at 36daab8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 6 days ago.

Activeupdated last month
metadata
{
  "author": "Upstash",
  "homepage": "https://upstash.com"
}

README badge

README badge for upstash/skills/upstash-ratelimit-js