mirror of
https://github.com/supabase/supabase.git
synced 2026-10-11 12:25:05 +03:00
This PR fixes some prettier issues: - Bump and unify all prettier versions to 3.7.3 across teh whole repo - Bump the SQL prettier plugin - When running `test:prettier`, check `mdx` files also - Run the new prettier format on all files --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
46 lines
1.9 KiB
Plaintext
46 lines
1.9 KiB
Plaintext
---
|
|
title: 'Rate limits'
|
|
subtitle: 'Rate limits protect your services from abuse'
|
|
---
|
|
|
|
Supabase Auth enforces rate limits on authentication endpoints to prevent abuse. Some rate limits are customizable, and you can configure them in your project [**Authentication** > **Rate Limits**](/dashboard/project/_/auth/rate-limits).
|
|
|
|
You can also manage rate limits using the Management API:
|
|
|
|
```bash
|
|
# Get your access token from https://supabase.com/dashboard/account/tokens
|
|
export SUPABASE_ACCESS_TOKEN="your-access-token"
|
|
export PROJECT_REF="your-project-ref"
|
|
|
|
# Get current rate limits
|
|
curl -X GET "https://api.supabase.com/v1/projects/$PROJECT_REF/config/auth" \
|
|
-H "Authorization: Bearer $SUPABASE_ACCESS_TOKEN" \
|
|
| jq 'to_entries | map(select(.key | startswith("rate_limit_"))) | from_entries'
|
|
|
|
# Update rate limits
|
|
curl -X PATCH "https://api.supabase.com/v1/projects/$PROJECT_REF/config/auth" \
|
|
-H "Authorization: Bearer $SUPABASE_ACCESS_TOKEN" \
|
|
-H "Content-Type: application/json" \
|
|
-d '{
|
|
"rate_limit_anonymous_users": 10,
|
|
"rate_limit_email_sent": 10,
|
|
"rate_limit_sms_sent": 10,
|
|
"rate_limit_verify": 10,
|
|
"rate_limit_token_refresh": 10,
|
|
"rate_limit_otp": 10,
|
|
"rate_limit_web3": 10
|
|
}'
|
|
```
|
|
|
|
## Rate limit behavior
|
|
|
|
Supabase Auth uses a token bucket algorithm for endpoint operations that are limited by IP address.
|
|
|
|
Each bucket has a maximum capacity of 30 requests. When the bucket is full, brief bursts of up to 30 requests can be allowed in a short period. Once the bucket empties, requests are rate limited until tokens refill. The rate limit defines the rate at which the bucket is refilled.
|
|
|
|
This means a client that has been idle will tolerate a brief spike in traffic, but sustained request above the rate limit are denied. When rate limits are exceeded, a **429 Too Many Requests** error is returned.
|
|
|
|
The table below shows the rate limit quotas and additional details for authentication endpoints.
|
|
|
|
<$Partial path="auth_rate_limits.mdx" />
|