CAPABILITIES

Limit

Managed integration preview

Give every action
a deliberate budget.

Set action budgets for verified browsers or authenticated server identities. Observe the impact, then explicitly enforce limits before your application handler runs.

REQUEST PATHIllustrative

Capacity + refill · per identity

  1. Resolve browser or identity
  2. Check shared action budget
  3. Admit or return retry guidance
  4. Run admitted action

Shared budgets. Application authority.

01 — IN YOUR CODE

Code opts in.Policy Studio sets the budget.

Mark the routes that need a budget. Capacity and refill live in Policy Studio, so a budget can change without a release.

Budget a browser or an identity

Use a verified browser budget alongside Verify, or resolve a trusted server subject from your own authentication.

  • A browser budget requires Verify and its browser collection.
  • A Limit-only route authenticates first and needs no browser collector.
  • Never use an identity the browser supplies; resolve it on the server.
server/routes.js
// Verify + per-browser Limit: browser collection is required.app.post("/api/signup",  mandate({ verify: true, limit: true }),  signupHandler); // Limit-only: authenticate first; no browser collector.app.post("/api/export", authenticateUser, mandate({  verify: false,  limit: true,  subject: req => req.user.id,}), exportHandler);

02 — HOW IT RUNS

Observe. Enforce. Pause.

New budgets start in Observe. Enforce is an explicit step, and Pause keeps the settings while you adjust them.

14:32POST /api/exportwithin budgetADMIT
14:32POST /api/exportbudget emptyWOULD 429
14:32POST /api/exportwithin budgetADMIT
14:31POST /api/exportbudget emptyWOULD 429
14:31POST /api/exportwithin budgetADMIT

Observe records admission attempts against the budget without blocking anything, so you can size capacity and refill on real traffic.

Sees: identity, route, capacity, refill, attempts

Explicit Limit Enforce rejects an exhausted budget before your handler runs, returning HTTP 429 with Retry-After.

Returns: admission, or 429 with Retry-After

Pause retains the configuration so a budget can be adjusted without recreating it.

Keeps: capacity, refill, subject selection

03 — SPECS

Tech specs

See what is inside the box.

Budget type

Token bucket: capacity plus continuous refill. It counts admission attempts, not successful purchases, and is not a strict rolling-window quota.

Identity

A verified browser (requires Verify) or a trusted server identity resolved from your application’s authentication.

Consistency

Shared admission keeps a budget consistent across participating application instances.

Modes

Observe by default, explicit Enforce, and Pause.

Responses

HTTP 429 with Retry-After when an enforced budget is exhausted. An active subject budget without a resolved subject returns 503.

Availability

Implemented in the Node managed integration candidate. Package publication and production activation are separate steps.