Skip to main content
Rate limit any endpoint exposed to the public — login, signup, password reset, forms. Without limits, abuse hits hard and fast.

Three axes

Per IP

Limit by source address. Best for unauthenticated endpoints.

Per user

Limit by user ID. Best for authenticated endpoints.

Per workspace / per resource

Limit by tenant. Best for shared rate budgets.
Combine: rate limit signup at 5 per IP per hour AND 10 per email per day.

Pattern in Convex

convex/rateLimit.ts
Call it from any mutation you want to limit:
A scheduled cleanup deletes events older than the longest window.

Where to limit

Beyond per-endpoint

For broader abuse patterns:
  • CAPTCHA / hCaptcha on signup and login.
  • Email verification before letting users do anything destructive.
  • Cost-aware rate limits: charge users credits for expensive operations (LLM calls, image generation), so abuse is self-limiting.

Auth best practices

Rate limiting auth endpoints.

Security overview

Where rate limiting fits.

API rate limits

The vly API’s built-in limits.
Last modified on April 18, 2026