CAPABILITIES
Limit
Managed integration preview
Give every action
a deliberate budget.
Set action budgets for verified browsers or authenticated server identities. Observe the impact, then explicitly enforce limits before your application handler runs.
Capacity + refill · per identity
- Resolve browser or identity
- Check shared action budget
- Admit or return retry guidance
- Run admitted action
Shared budgets. Application authority.
01 — IN YOUR CODE
Code opts in.Policy Studio sets the budget.
Mark the routes that need a budget. Capacity and refill live in Policy Studio, so a budget can change without a release.
Budget a browser or an identity
Use a verified browser budget alongside Verify, or resolve a trusted server subject from your own authentication.
- A browser budget requires Verify and its browser collection.
- A Limit-only route authenticates first and needs no browser collector.
- Never use an identity the browser supplies; resolve it on the server.
// Verify + per-browser Limit: browser collection is required.app.post("/api/signup", mandate({ verify: true, limit: true }), signupHandler); // Limit-only: authenticate first; no browser collector.app.post("/api/export", authenticateUser, mandate({ verify: false, limit: true, subject: req => req.user.id,}), exportHandler);
02 — HOW IT RUNS
Observe. Enforce. Pause.
New budgets start in Observe. Enforce is an explicit step, and Pause keeps the settings while you adjust them.
Observe records admission attempts against the budget without blocking anything, so you can size capacity and refill on real traffic.
Sees: identity, route, capacity, refill, attempts
Explicit Limit Enforce rejects an exhausted budget before your handler runs, returning HTTP 429 with Retry-After.
Returns: admission, or 429 with Retry-After
Pause retains the configuration so a budget can be adjusted without recreating it.
Keeps: capacity, refill, subject selection
03 — SPECS
Tech specs
See what is inside the box.
Budget type
Token bucket: capacity plus continuous refill. It counts admission attempts, not successful purchases, and is not a strict rolling-window quota.
Identity
A verified browser (requires Verify) or a trusted server identity resolved from your application’s authentication.
Consistency
Shared admission keeps a budget consistent across participating application instances.
Modes
Observe by default, explicit Enforce, and Pause.
Responses
HTTP 429 with Retry-After when an enforced budget is exhausted. An active subject budget without a resolved subject returns 503.
Availability
Implemented in the Node managed integration candidate. Package publication and production activation are separate steps.