Create an Upstash Redis database and use @upstash/ratelimit to cap requests per user or IP, so bots can't run up your bill.
Add a rate limit so each user can only hit my AI endpoint 10 times a minute
How it works
- Create an Upstash Redis database: Redis is a very fast store for small counters. Vovy creates a database in the Upstash console in a region close to your host.
- Copy the REST URL and token: Vovy copies UPSTASH_REDIS_REST_URL and UPSTASH_REDIS_REST_TOKEN into your .env and Vercel's environment variables.
- Add the rate limiter: Vovy installs @upstash/ratelimit and adds a check to your endpoint, like 10 requests per minute per signed-in user or IP address.
- Return a friendly error: When someone hits the limit, your API returns status 429 Too Many Requests and your app shows a clear message instead of breaking.
- Test the limit: Vovy fires requests past the limit and shows a card: which ones passed, which got 429, and when the counter resets.
What you provide
- An Upstash account
- The endpoint to protect
- Your limit, like 10 a minute
What you get
- An Upstash Redis database
- Rate limiting on your endpoint
- Friendly 429 handling
- Test results card
FAQ
Is Upstash free?
Upstash Redis has a free tier with a monthly command allowance that covers most small apps. Beyond it, you pay per request.
Why not just count in my database?
You can, but Redis is built for fast counters that expire, so it adds almost no delay to each request.
Should I limit by IP or by user?
By user when they're signed in, since many people can share one IP. Use IP for logged-out endpoints.
Related tasks
All tasks