All skills
upstash avatar

/upstash-ratelimit-js

@36daab8
by upstashupstash/skills27 stars
7

Rate limiting for serverless and edge apps with the @upstash/ratelimit TypeScript/JavaScript SDK backed by Upstash Redis. Use when adding a rate limiter or throttling to an API route, Next.js middleware, Vercel Edge, Cloudflare Workers, or any HTTP endpoint; returning 429 Too Many Requests; choosing between fixed window, sliding window, and token bucket algorithms; limiting per user, IP, API key, or tenant with prefixes and custom keys; protecting login, signup, form, or AI endpoints from abuse, bots, and brute force; using deny lists, ephemeral caching, analytics, timeouts, and multi-region rate limits; or estimating the Redis command cost of rate limiting. Also use when the user says rate limit, rate-limiting, throttle, quota, request limits, or traffic protection.

Use this Skill: https://skilld.dev/gh/upstash/skills/upstash-ratelimit-js

This session only. Nothing lands on disk.

traffic-protection.md

≈590 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Traffic Protection

This skill documents how to use deny lists and automatic IP protection in the Upstash Ratelimit TypeScript SDK. It explains configuration, behavior, caching, update patterns, and common pitfalls.


Deny Lists

Deny lists block requests based on IP, user agent, country, or identifier. Enable protection by setting enableProtection: true when creating your Ratelimit client.

Example usage:

const ratelimit = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.slidingWindow(10, "10 s"),
  enableProtection: true,
  analytics: true,
});

const result = await ratelimit.limit("userId", {
  ip: "203.0.113.5",
  userAgent: "malicious-bot",
  country: "CN",
});

await result.pending; // analytics sync

if (!result.success && result.reason === "denyList") {
  console.log("Blocked value:", result.deniedValue);
}

Behavior & Pitfalls

  • Exact match only; pattern matching is not supported.
  • Denied values are cached for 1 minute to reduce Redis load. Removal from the deny list may take up to a minute to propagate.
  • Adding a value propagates instantly.
  • Dashboard manages all deny list entries; analytics can show aggregated blocks.

Auto IP Deny List

Automatically blocks IPs aggregated from >30 open‑source abuse lists (via GitHub's ipsum repository). Updates occur daily at 2 AM UTC.

Enable protection:

const ratelimit = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.slidingWindow(10, "10 s"),
  enableProtection: true,
});

const { success, pending } = await ratelimit.limit("userId", { ip: "203.0.113.77" });
await pending; // ensures async sync completion

Update Flow

  • First call to limit after 2 AM UTC triggers asynchronous list refresh.
  • Request results are returned immediately; updates complete in the background.
  • Use the pending promise when accuracy depends on the sync.

Dashboard Integration

  • All auto‑blocked IPs appear in the "Denied" section.
  • Feature can be disabled from the Upstash Console without disabling standard deny lists.

Common Mistakes

  • Forgetting to pass ip, userAgent, or country to limit → protection does not apply.
  • Expecting pattern or CIDR matches; only exact strings are checked.
  • Confusing auto IP deny list with manual deny list entries; both operate independently.

Source: SKILL.md on GitHub

No alerts17d3 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides comprehensive documentation and implementation examples for the Upstash Rate Limit SDK. It adheres to security best practices, such as recommending environment variables for credential management and using official vendor packages.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

Signed by skilld at 36daab8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 days ago.

Activeupdated last month
metadata
{
  "author": "Upstash",
  "homepage": "https://upstash.com"
}

README badge

README badge for upstash/skills/upstash-ratelimit-js