Usage quotas

A quota limits how many times an operation can run within a rolling window. Whoever reaches the limit gets the message you wrote for that rule.

Rules on the operation

Quotas are declared in config, on the operation, as a list of rules. A rule sets points, the most runs allowed in the window, and duration, the window's length in seconds. Zero points means unlimited. The window slides: each run is timestamped, and runs older than the duration drop out of the count.

Whose runs are counted

A rule can count per signed-in user, so each person has an allowance of their own. A quota can also be shared across a wider pool.

At the limit

The call fails with RATE_LIMITED and the rule's message. A rule with no message returns an error that states the usage, the limit and the time the window resets.

Tiers from rule order

Rules are evaluated top to bottom and the first match wins. A rule can be limited to the members of a segment, which gives a tiered setup: an unlimited rule for a segment of paying users, followed by a metered rule for everyone else.

Order of checks and failure

Quotas are checked after preconditions pass. If the counter store cannot be read, a rule allows the call by default, and a rule can be set to fail closed and refuse. A quota meters operations only.

Read the detail

The operations config reference lists every field on a quota rule and shows the tiered pattern.