Handle Vercel API rate limits, implement retry logic, and configure WAF rate limiting.

MITAuto-check passedBackend & APIs

Install Vercel Rate Limits

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill vercel-rate-limits -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace vercel-rate-limits --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/vercel-rate-limits .claude/skills/vercel-rate-limits && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vercel-rate-limits
GitHub stars
2.8k
Token cost
~1.9k tokens
SKILL.md length
372 words
Files
4 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Handle Vercel API rate limits, implement retry logic, and configure WAF rate limiting.

  • Works in 5 steps: Vercel REST API Rate Limits → Implement Retry with Backoff for Vercel… → Proactive Rate Limit Avoidance → …
  • Hitting 429 errors
  • SKILL.md covers Overview, Prerequisites, Instructions and Platform Concurrency Limits, plus 5 more sections
  • Calls npm

What it does

Vercel Rate Limits is an agent skill from jeremylongshore/tons-of-skills-marketplace. Handle Vercel API rate limits, implement retry logic, and configure WAF rate limiting. Use when hitting 429 errors, implementing retry logic, or setting up rate limiting for your Vercel-deployed API endpoints. Trigger with phrases like "vercel rate limit", "vercel throttling", "vercel 429", "vercel retry", "vercel backoff", "vercel WAF rate limit".

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/errors.md`, `references/examples.md` and `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Rate limiting. It works with Vercel. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Hitting 429 errors
  • Implementing retry logic
  • Setting up rate limiting for your Vercel-deployed API endpoints
  • With phrases like vercel rate limit

Example prompts

  • “vercel rate limit”
  • “vercel throttling”
  • “vercel 429”
  • “/vercel-rate-limits”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Vercel REST API Rate Limits
  2. Implement Retry with Backoff for Vercel API
  3. Proactive Rate Limit Avoidance
  4. Protect Your Own Endpoints — Vercel WAF Rate Limiting
  5. Custom Rate Limiting with Edge Config

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • vercel.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Vercel Rate Limits loads about 1.9k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 372 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 372 words, ~1,905 tokens.

Download SKILL.mdSave it as .claude/skills/vercel-rate-limits/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
vercel-rate-limits
description
Handle Vercel API rate limits, implement retry logic, and configure WAF rate limiting. Use when hitting 429 errors, implementing retry logic, or setting up rate limiting for your Vercel-deployed API endpoints. Trigger with phrases like "vercel rate limit", "vercel throttling", "vercel 429", "vercel retry", "vercel backoff", "vercel WAF rate limit".
allowed-tools
Read, Write, Edit
compatibility
Designed for Claude Code
version
1.18.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, vercel, api, rate-limiting, security

Vercel Rate Limits

Overview

Handle Vercel REST API rate limits with proper retry logic, and configure Vercel's WAF rate limiting SDK to protect your deployed API endpoints from abuse. Covers both consuming the Vercel API (outbound) and protecting your own functions (inbound).

Prerequisites

  • Vercel CLI installed and authenticated
  • Understanding of HTTP 429 status codes
  • For WAF rate limiting: Vercel Pro or Enterprise plan

Instructions

Step 1: Vercel REST API Rate Limits

The Vercel REST API enforces rate limits per endpoint. When exceeded, the API returns HTTP 429 with rate limit headers:

HTTP/1.1 429 Too Many Requests
X-RateLimit-Limit: 100
X-RateLimit-Remaining: 0
X-RateLimit-Reset: 1711152000
Retry-After: 60

Known API limits:

Endpoint CategoryRate Limit
Deployments (create)100/hour per project
Deployments (list/get)500/min
Projects (CRUD)200/min
Environment variables200/min
Domains200/min
Teams200/min
DNS records200/min
General API120 requests/min (default)
Step 2: Implement Retry with Backoff for Vercel API
typescript
// lib/rate-limit-handler.ts
interface RateLimitInfo {
  limit: number;
  remaining: number;
  reset: number; // Unix timestamp
}

function parseRateLimitHeaders(headers: Headers): RateLimitInfo {
  return {
    limit: Number(headers.get('X-RateLimit-Limit') ?? 100),
    remaining: Number(headers.get('X-RateLimit-Remaining') ?? 100),
    reset: Number(headers.get('X-RateLimit-Reset') ?? 0),
  };
}

async function vercelFetchWithRetry(
  url: string,
  options: RequestInit,
  maxRetries = 3
): Promise<Response> {
  for (let attempt = 0; attempt <= maxRetries; attempt++) {
    const res = await fetch(url, options);

    if (res.status !== 429) return res;

    if (attempt === maxRetries) {
      throw new Error(`Rate limited after ${maxRetries} retries: ${url}`);
    }

    // Use Retry-After header if present, otherwise exponential backoff
    const retryAfter = res.headers.get('Retry-After');
    const waitMs = retryAfter
      ? Number(retryAfter) * 1000
      : Math.min(1000 * Math.pow(2, attempt) + Math.random() * 1000, 30000);

    console.warn(`Rate limited (attempt ${attempt + 1}/${maxRetries}). Waiting ${Math.round(waitMs)}ms...`);
    await new Promise(r => setTimeout(r, waitMs));
  }
  throw new Error('Unreachable');
}
Step 3: Proactive Rate Limit Avoidance
typescript
// lib/rate-limiter.ts
// Track remaining quota and slow down before hitting the wall
class VercelRateLimiter {
  private remaining = 100;
  private resetAt = 0;

  async throttle(): Promise<void> {
    // If near the limit, wait until reset
    if (this.remaining < 5) {
      const waitMs = Math.max(0, this.resetAt * 1000 - Date.now()) + 1000;
      console.warn(`Near rate limit (${this.remaining} remaining). Waiting ${waitMs}ms...`);
      await new Promise(r => setTimeout(r, waitMs));
    }
  }

  update(headers: Headers): void {
    this.remaining = Number(headers.get('X-RateLimit-Remaining') ?? this.remaining);
    this.resetAt = Number(headers.get('X-RateLimit-Reset') ?? this.resetAt);
  }
}
Step 4: Protect Your Own Endpoints — Vercel WAF Rate Limiting

Vercel's WAF provides built-in rate limiting for your deployed functions:

typescript
// middleware.ts — WAF rate limiting via Vercel Firewall SDK
import { ipAddress } from '@vercel/functions';
import { checkRateLimit } from '@vercel/firewall';

export async function middleware(request: Request) {
  const ip = ipAddress(request) ?? '127.0.0.1';

  // Rate limit: 100 requests per 60 seconds per IP
  const { rateLimited } = await checkRateLimit('api-limit', {
    key: ip,
    limit: 100,
    window: '60s',
  });

  if (rateLimited) {
    return new Response(
      JSON.stringify({ error: 'Too many requests. Please try again later.' }),
      { status: 429, headers: { 'Content-Type': 'application/json', 'Retry-After': '60' } }
    );
  }
}

export const config = {
  matcher: '/api/:path*',
};

Install: npm install @vercel/firewall @vercel/functions

Step 5: Custom Rate Limiting with Edge Config
typescript
// api/rate-limited-endpoint.ts
import { get } from '@vercel/edge-config';

export const config = { runtime: 'edge' };

// Simple in-memory sliding window (per-isolate, not global)
const windowMs = 60_000;
const maxRequests = 50;
const requests = new Map<string, number[]>();

function isRateLimited(key: string): boolean {
  const now = Date.now();
  const timestamps = (requests.get(key) ?? []).filter(t => now - t < windowMs);
  timestamps.push(now);
  requests.set(key, timestamps);
  return timestamps.length > maxRequests;
}

export default async function handler(request: Request): Promise<Response> {
  const ip = request.headers.get('x-forwarded-for') ?? 'unknown';

  if (isRateLimited(ip)) {
    return Response.json({ error: 'Rate limit exceeded' }, { status: 429 });
  }

  return Response.json({ data: 'ok' });
}

Platform Concurrency Limits

PlanConcurrent ExecutionsBuilds/Hour
Hobby1032
Pro1,0006,000/day
Enterprise100,000Custom

Output

  • Vercel API calls wrapped with automatic retry and backoff
  • Rate limit headers parsed and monitored proactively
  • WAF rate limiting protecting deployed API endpoints
  • Custom per-IP rate limiting for fine-grained control
Show full SKILL.md (153 more words)Show less

Error Handling

ErrorCauseSolution
429 Too Many RequestsAPI rate limit exceededUse vercelFetchWithRetry() wrapper
FUNCTION_THROTTLEDConcurrent execution limit hitReduce parallelism or upgrade plan
Rate limit not appliedMiddleware not matching routesCheck config.matcher pattern
In-memory rate limit resetsEdge function isolate recycledUse Redis or Vercel KV for persistent state

Examples

Apply a fair API limit without blocking trusted automation

Start with a per-route, per-principal limit in preview and exempt only named, authenticated service identities through a reviewed allowlist. Exercise normal, burst, and retry behavior with synthetic clients, ensuring 429 responses include a safe retry interval and do not reveal internal quota details. Monitor false positives after rollout; if a critical integration is blocked, use a narrowly scoped temporary limit adjustment, then correct the policy instead of disabling rate limiting.

Resources

Next Steps

For security best practices, see vercel-security-basics.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/.curated/vercel-rate-limits of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/errors.md
  • references/examples.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Vercel Rate Limits next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vercel Rate Limits compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vercel Rate Limits this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: PassMIT
Frontmcp Configagentfront/frontmcp146—~7kAutomated safety check: PassApache-2.0
Upstash Redisgithub/awesome-copilot40k—~1.7kAutomated safety check: PassMIT
Vercel Firewallvercel/vercel-plugin301—~5.4kAutomated safety check: NotesCustom licence
Browser Toolsyonatangross/orchestkit292—~6.1kAutomated safety check: PassMIT
cmux Backend Rulesmanaflow-ai/cmux28k1 repos~682Automated safety check: PassCustom licence

Similar skills

  • Frontmcp Config

    agentfront/frontmcp

    A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.

    146 GitHub stars~7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Upstash Redis

    github/awesome-copilot

    Official

    Use Redis over HTTP from serverless and edge runtimes with @upstash/redis, and add rate limiting with @upstash/ratelimit.

    40k GitHub stars~1.7k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Vercel Firewall

    vercel/vercel-plugin

    Official

    Vercel Firewall expert guidance — automatic DDoS mitigation, the Vercel WAF (custom rules, IP blocking, managed rulesets, rate limiting), Attack Mode, system bypass, bot management, and the vercel…

    301 GitHub stars~5.4k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Browser Tools

    yonatangross/orchestkit

    Security wrapper over the upstream agent-browser skill, adding URL blocklisting, rate limiting, robots.txt enforcement, and scraping guardrails.

    292 GitHub stars~6.1k tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • cmux Backend Rules

    manaflow-ai/cmux

    Sets the backend TypeScript and Cloud VM rules for cmux: Effect-based services, thin route handlers, Postgres as source of truth, migrations and provider secrets.

    28k GitHub starsUsed in 1 repo~682 tokens
    Backend & APIsAuto-check passed
  • Golive

    mikehasa/golive-skill

    Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).

    1.3k GitHub stars~13k tokensUpdated 7 days ago
    Backend & APIsAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Vercel Rate Limits

What does Vercel Rate Limits do?

Handle Vercel API rate limits, implement retry logic, and configure WAF rate limiting. Vercel Rate Limits is an agent skill from jeremylongshore/tons-of-skills-marketplace. Handle Vercel API rate limits, implement retry logic, and configure WAF rate limiting.

When should I use Vercel Rate Limits?

Vercel Rate Limits fits situations like: hitting 429 errors; implementing retry logic; setting up rate limiting for your Vercel-deployed API endpoints; with phrases like vercel rate limit.

How do I install Vercel Rate Limits in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill vercel-rate-limits -a claude-code`. Or copy the skill folder (skills/.curated/vercel-rate-limits in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/vercel-rate-limits in your project. Claude Code loads it when a task matches its description.

How do I install Vercel Rate Limits in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill vercel-rate-limits -a codex`. Or copy the skill folder (skills/.curated/vercel-rate-limits in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/vercel-rate-limits in your project. Codex loads it when a task matches its description.

Can I use Vercel Rate Limits in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill vercel-rate-limits -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vercel-rate-limits, .gemini/skills/vercel-rate-limits, .github/skills/vercel-rate-limits and .opencode/skills/vercel-rate-limits in your project.

What does Vercel Rate Limits need to run?

Going by SKILL.md and its folder, Vercel Rate Limits needs the command-line tools its instructions call (npm). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Vercel Rate Limits access the network?

SKILL.md names 1 domain. As links in the text: vercel.com. This is read from the text; nothing was executed.

Is Vercel Rate Limits safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vercel Rate Limits use?

Vercel Rate Limits is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vercel Rate Limits use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 970 tokens, read only when the agent opens those files.

What are the alternatives to Vercel Rate Limits?

Skills that share tags, products or a category with Vercel Rate Limits: Frontmcp Config (agentfront/frontmcp, 146 stars), Upstash Redis (github/awesome-copilot, 40k stars), Vercel Firewall (vercel/vercel-plugin, 301 stars) and Browser Tools (yonatangross/orchestkit, 292 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vercel Rate Limits?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.