Skip to content

docs(self-hosting): document the v2 per-IP limit that applies without billing - #8453

Open
Rajkumar2002-Rk wants to merge 1 commit into
simstudioai:stagingfrom
Rajkumar2002-Rk:docs/v2-preauth-ip-limit
Open

Rajkumar2002-Rk wants to merge 1 commit into
simstudioai:stagingfrom
Rajkumar2002-Rk:docs/v2-preauth-ip-limit

Conversation

@Rajkumar2002-Rk

Copy link
Copy Markdown

Summary

The Limits section says self-hosted installs with billing disabled have "no rate limits", but the v2 API always enforces a fixed per-IP limit before auth (V2_PREAUTH_IP_LIMIT in apps/sim/lib/api/server/routes/v2-json-route.ts: 600 burst, 300 per minute). This changes "no rate limits" to "no plan rate limits" and adds a short note on that limit, how it behaves with Docker Compose, and AUTH_TRUSTED_PROXIES behind a reverse proxy.

Refs #8452

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • Other: ___________

Testing

Docs only. Checked the numbers against V2_PREAUTH_IP_LIMIT on staging, and reproduced the limit on a self-hosted install with billing off: 800 quick requests to POST /api/v2/workflows/{id}/execute with an invalid key gave 600 × 401, then 429 with x-ratelimit-limit: 600.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (docs only, no tests affected)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 30, 2026

Copy link
Copy Markdown

@Rajkumar2002-Rk is attempting to deploy a commit to the Sim Team on Vercel.

A member of the Team first needs to authorize it.

@greptile-apps

greptile-apps Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[Low risk] Documents API rate limits in self-hosting guide.

The PR appears safe to merge, with a non-blocking documentation correction recommended.

Findings

  1. P2 Other limits still apply ▶

Summary

The PR clarifies that disabling billing removes plan rate limits, then documents the v2 pre-authentication per-IP limit and deployment-specific IP handling.

  • The v2 limit details agree with the implementation.
  • The callout should not imply that v2 is the only route with a billing-independent limit.

Reviews (1) · Last reviewed commit: "docs(self-hosting): document the v2 per-..."

</Callout>

<Callout type="info">
One limit applies regardless of billing: the v2 API (`/api/v2/...`) allows each client IP a burst of 600 requests, then 300 per minute, checked before authentication. `BILLING_ENABLED` and the variables above don't change it. With Docker Compose, requests from the host machine all arrive from the bridge gateway address and share one budget. Behind a reverse proxy, set `AUTH_TRUSTED_PROXIES` so each client is counted by its own address.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Other limits still apply

“One limit applies regardless of billing” makes the v2 limit sound like the only exception. Other routes have independent limits too: the contact endpoint, for example, enforces a per-IP limit. Operators investigating a 429 on those routes could mistakenly look to the listed plan variables for a way to change it. Please avoid presenting the v2 limit as the sole exception.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant