Protect
every
endpoint.
Four rate limiting strategies that adapt to any traffic pattern. Real-time analytics on every decision. Plan-based quota enforcement that scales with your business.
Built for
production.
Everything you need to enforce rate limits reliably across your entire API surface.
Four strategies, one API
Fixed window, token bucket, leaky bucket, sliding window — each tuned for different traffic shapes. Switch between them without changing your integration.
Sub-millisecond decisions
Every allow or deny is computed atomically. The fast path adds under 1ms to your request cycle, even under sustained traffic spikes.
Real-time analytics
Every decision lands in an analytics store the moment it's made. Query allow/block rates, top endpoints, and traffic patterns live — no waiting for batch jobs.
Per-key overrides
Your enterprise customers need higher limits. Grant them with a single API call. Overrides stack cleanly on top of your plan defaults without any code changes.
Scoped API keys
Issue read-only, write, or admin keys to your customers. Revoke any key instantly. Set expiration dates that enforce themselves.
Live traffic streaming
Subscribe to a WebSocket stream for any key or tenant and watch decisions arrive in real time. Build monitoring dashboards that actually reflect right now.
How it works
Three steps.
That's it.
Create a key
Generate an API key for each customer or service. Assign scopes — read, write, or admin — and optionally set an expiration date.
Choose a strategy
Pick the algorithm that matches your traffic shape. Apply it at the key level, the tenant level, or globally. Override it per key anytime.
Watch the data
Every decision flows into analytics automatically. Filter by key, endpoint, status, or time range. Spot patterns before they become incidents.
Pricing
Simple,
transparent.
Start free. Upgrade when you need more strategies or higher volume.
Your API is
ready. Is your
rate limiter?
Free tier. No card required.