All skills
upstash avatar

/upstash-ratelimit-js

@36daab8
by upstashupstash/skills27 stars
7

Rate limiting for serverless and edge apps with the @upstash/ratelimit TypeScript/JavaScript SDK backed by Upstash Redis. Use when adding a rate limiter or throttling to an API route, Next.js middleware, Vercel Edge, Cloudflare Workers, or any HTTP endpoint; returning 429 Too Many Requests; choosing between fixed window, sliding window, and token bucket algorithms; limiting per user, IP, API key, or tenant with prefixes and custom keys; protecting login, signup, form, or AI endpoints from abuse, bots, and brute force; using deny lists, ephemeral caching, analytics, timeouts, and multi-region rate limits; or estimating the Redis command cost of rate limiting. Also use when the user says rate limit, rate-limiting, throttle, quota, request limits, or traffic protection.

Use this Skill: https://skilld.dev/gh/upstash/skills/upstash-ratelimit-js

This session only. Nothing lands on disk.

methods-getting-started.md

≈487 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Upstash Ratelimit Methods (TypeScript)

This document provides a focused, practical reference for all Ratelimit methods. Each section includes direct examples, usage patterns, and common pitfalls.

limit

Primary method for checking and consuming tokens.

const { success, remaining, reset, reason, pending } = await ratelimit.limit(
  identifier,
  {
    rate: 2,          // optional: consume N tokens
    ip: req.ip,       // optional: used for deny‑list checks
    userAgent: ua,    // optional
    country: geo?.country,
  }
);

if (!success) return "blocked";

// In Cloudflare/Vercel Edge, flush async work
context.waitUntil(pending);

Notes:

  • rate lets a request consume more than 1 token.
  • reason can be: timeout, cacheBlock, denyList, or undefined.
  • When analytics or MultiRegion is enabled, always handle pending in serverless environments.

blockUntilReady

Waits for a request to become allowed instead of rejecting immediately.

const { success } = await ratelimit.blockUntilReady("id", 30_000);
if (!success) return "still blocked after timeout";

resetUsedTokens

Clears the state for an identifier.

await ratelimit.resetUsedTokens("user123");

Useful when granting temporary resets or admin overrides.

getRemaining

Read-only view of remaining quota.

const { remaining, reset } = await ratelimit.getRemaining("user123");

Common use cases:

  • Dashboard queries
  • Showing users their remaining quota

setDynamicLimit

Overrides the global limit at runtime.

await ratelimit.setDynamicLimit({ limit: 5 });   // set
await ratelimit.setDynamicLimit({ limit: false }); // remove

Notes:

  • Requires dynamicLimits: true in constructor.
  • Applies to all future rate checks.

getDynamicLimit

Fetch the currently active dynamic limit.

const { dynamicLimit } = await ratelimit.getDynamicLimit();

Returns null when no override is active.

Source: SKILL.md on GitHub

No alerts17d3 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides comprehensive documentation and implementation examples for the Upstash Rate Limit SDK. It adheres to security best practices, such as recommending environment variables for credential management and using official vendor packages.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

Signed by skilld at 36daab8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 6 days ago.

Activeupdated last month
metadata
{
  "author": "Upstash",
  "homepage": "https://upstash.com"
}

README badge

README badge for upstash/skills/upstash-ratelimit-js