Usage quotas
A quota limits how many times an operation can run within a rolling window. Whoever reaches the limit gets the message you wrote for that rule.
Rules on the operation
Quotas are declared in config, on the operation, as a list of rules. A rule sets points, the most runs allowed in the window, and duration, the window's length in seconds. Zero points means unlimited. The window slides: each run is timestamped, and runs older than the duration drop out of the count.
Whose runs are counted
A rule can count per signed-in user, so each person has an allowance of their own. A quota can also be shared across a wider pool.
At the limit
The call fails with RATE_LIMITED and the rule's message. A rule with no message returns an error that states the usage, the limit and the time the window resets.
Tiers from rule order
Rules are evaluated top to bottom and the first match wins. A rule can be limited to the members of a segment, which gives a tiered setup: an unlimited rule for a segment of paying users, followed by a metered rule for everyone else.
Order of checks and failure
Quotas are checked after preconditions pass. If the counter store cannot be read, a rule allows the call by default, and a rule can be set to fail closed and refuse. A quota meters operations only.
Read the detail
The operations config reference lists every field on a quota rule and shows the tiered pattern.