Three axes
Per IP
Limit by source address. Best for unauthenticated endpoints.
Per user
Limit by user ID. Best for authenticated endpoints.
Per workspace / per resource
Limit by tenant. Best for shared rate budgets.
Pattern in Convex
convex/rateLimit.ts
Where to limit
Beyond per-endpoint
For broader abuse patterns:- CAPTCHA / hCaptcha on signup and login.
- Email verification before letting users do anything destructive.
- Cost-aware rate limits: charge users credits for expensive operations (LLM calls, image generation), so abuse is self-limiting.
Related
Auth best practices
Rate limiting auth endpoints.
Security overview
Where rate limiting fits.
API rate limits
The vly API’s built-in limits.
