Skip to main content
caps how often something can happen in a time window. API Management gives you two ways to do it: a standalone API you call with any identifier you choose, or limits on a key or identity that are checked when the key is verified. (The Compute gateway’s rate limit policy is a separate feature. See the glossary.)

Choose a rate limit

Use the standalone API when the endpoint has no key (sign-up, password reset) or when you want to limit something other than the key holder. Use key and identity limits when the request already carries a key, so the check happens during the verification you already make. Both count requests the same way. See How rate limiting works.

A first rate limit

You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys, and pass it as Authorization: Bearer <root key>. See Permission reference for every permission.
The root key needs ratelimit.*.limit, plus ratelimit.*.create_namespace the first time a namespace name is used.
The namespace email.send names what you’re limiting. The identifier user_123 is who’s being counted. Each user gets ten calls per minute, and the eleventh returns success: false until the window moves on. In the TypeScript SDK, the same call is unkey.ratelimit.limit({ namespace, identifier, limit, duration }).

Next steps

How rate limiting works

Sliding windows, regional counters, cross-region convergence, and what remaining and reset mean.

ratelimit.limit and multiLimit

Request and response fields, bounds, namespaces, cost, and atomic multi-limit checks.

Rate limit overrides

Give one identifier or a wildcard pattern a different limit without changing code.

Key and identity rate limits

Named limits on keys and identities, auto-apply, cost, and inline limits at verification.
Last modified on September 29, 2026