Skip to content

v2 API rate limits self-hosted installs by IP even with billing disabled #8452

Description

@Rajkumar2002-Rk

The self-hosting docs (Environment Variables, "Limits") say installs with billing disabled "run without plan limits: no rate limits". The v2 API still enforces a fixed per-IP limit before auth: V2_PREAUTH_IP_LIMIT in apps/sim/lib/api/server/routes/v2-json-route.ts (600 burst, 300 per minute). It isn't affected by BILLING_ENABLED or the RATE_LIMIT_FREE_* variables, and there's no way to change it.

On a Docker Compose install, every request from the host arrives from the bridge gateway (172.19.0.1 here), so all local callers share one bucket. A batch job running sync executes with a log fetch after each one hit it and got 429 RATE_LIMITED. The server logs show storageKey: v2:preauth:ip:172.19.0.1.

Repro (billing off, no RATE_LIMIT_* set): send 800 quick requests to POST /api/v2/workflows/{id}/execute, even with an invalid API key. The first 600 return 401 and the rest return 429 with x-ratelimit-limit: 600.

At minimum it would help to mention this limit in the Limits section. It might also make sense to let self-hosters raise it with an env var, or to skip it when billing is disabled, but that's your call since it's there for abuse protection. Happy to send a docs PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions