OSS TanbouSign in with GitHub

add HTTP-based distributed rate limiting to serverless, edge, and Next.js APIs

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
2,049
Primary language
TypeScript
License
MIT
Repository last updated
Sep 25, 2026
On this page

Overview

Upstash Rate Limit is a connectionless TypeScript rate-limiting library backed by Upstash Redis. It shares state over HTTP, making request controls easier to apply across distributed instances in environments such as Next.js, Vercel Edge, and Cloudflare Workers.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Evaluate limits per identifier against shared Redis state

The README example configures a sliding window of 10 requests per 10 seconds and uses a user ID, API key, IP address, or constant string as the identifier passed to limit(). A custom key prefix can also be configured.

Sources: [1]

Version 2.2.0 fixes window and token-bucket boundary cases

The 2.2.0 release fixes the last-token case for cached fixed windows, avoids negative blockUntilReady timeouts, rejects token-bucket requests that exceed remaining tokens, and adds decimal values plus a week unit to duration parsing.

Sources: [2]

Best fit

Fits rate limiting where serverless or edge processes cannot share in-memory counters

The README targets AWS Lambda, Vercel, Cloudflare Workers and Pages, Vercel Edge, Fastly Compute@Edge, and Next.js, and links to a complete Next.js example.

Sources: [1]

Before adoption

Provision Upstash Redis as the backing store and design credential and failure handling

Usage requires an Upstash Redis client and REST credentials. In production, keep the URL and token in secret management and test how Redis latency or temporary failures affect the API's rate-limit decision path.

Sources: [1]

Make identifier, prefix, and telemetry choices explicit per deployment

When multiple applications share Redis, use prefixes to avoid key collisions and verify that identifiers represent the intended caller scope. SDK name/version telemetry can be disabled with enableTelemetry: false or UPSTASH_DISABLE_TELEMETRY.

Sources: [1]

Official sources

  1. [1]Upstash Rate Limit v2.2.0 README(2026-10-06)
  2. [2]Upstash Rate Limit v2.2.0 release(2026-10-06)
Supplemental curator note

It fits serverless and edge APIs whose processes cannot share in-memory counters. Validate identifiers and prefixes, Upstash Redis credentials, failure behavior, and telemetry policy before production.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/upstash/ratelimit-js.git
  2. 2

    Enter the repository

    cd ratelimit-js
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

2,049 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
5
Open PRs
5

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • rate-limiting
  • redis
  • serverless
  • upstash
  • upstash-ratelimit
  • upstash-sdk
Stars
2,049
Forks
51
Watchers
12
Open issues
4
Contributors
28
Owner type
Organization
Primary language
TypeScript
License
MIT
Repository last updated
Sep 25, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?