Agent skill

API Rate Limiting

by secondsky in secondsky/claude-skills

Implements API rate limiting using token bucket, sliding window, and Redis-based algorithms to protect against abuse.

MITAuto-check passedBackend & APIs

Install API Rate Limiting

skills CLI
$ npx skills add secondsky/claude-skills --skill api-rate-limiting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/claude-skills api-rate-limiting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/api-rate-limiting/skills/api-rate-limiting .claude/skills/api-rate-limiting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-rate-limiting
GitHub stars
227
Used in
1 other repo
Token cost
~497 tokens
SKILL.md length
86 words
Files
1
Skills in repo
169
Repo updated
First seen
Licence
MIT

At a glance

Implements API rate limiting using token bucket, sliding window, and Redis-based algorithms to protect against abuse.

  • Securing public APIs
  • SKILL.md covers Algorithms, Token Bucket (Node.js), Express Middleware and Response Headers, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Implementing tiered access

What it does

API Rate Limiting is an agent skill from secondsky/claude-skills. Implements API rate limiting using token bucket, sliding window, and Redis-based algorithms to protect against abuse. Use when securing public APIs, implementing tiered access, or preventing denial-of-service attacks.

Its SKILL.md is about 500 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Rate limiting. It works with Redis. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.

When your agent uses it

  • Securing public APIs
  • Implementing tiered access
  • Preventing denial-of-service attacks

Example prompts

  • “Use the api-rate-limiting skill to implement API rate limiting using token bucket, sliding window, and Redis-based algorithms to protect against abuse”
  • “/api-rate-limiting”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Rate Limiting loads about 497 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 86 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~497

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 86 words, ~497 tokens.

Download SKILL.mdSave it as .claude/skills/api-rate-limiting/SKILL.md (or your agent's skills folder).
name
api-rate-limiting
description
Implements API rate limiting using token bucket, sliding window, and Redis-based algorithms to protect against abuse. Use when securing public APIs, implementing tiered access, or preventing denial-of-service attacks.
license
MIT

API Rate Limiting

Protect APIs from abuse using rate limiting algorithms with per-user and per-endpoint strategies.

Algorithms

AlgorithmProsCons
Token BucketHandles bursts, smoothMemory per user
Sliding WindowAccurateMemory intensive
Fixed WindowSimpleBoundary spikes

Token Bucket (Node.js)

javascript
class TokenBucket {
  constructor(capacity, refillRate) {
    this.capacity = capacity;
    this.tokens = capacity;
    this.refillRate = refillRate; // tokens per second
    this.lastRefill = Date.now();
  }

  consume() {
    this.refill();
    if (this.tokens >= 1) {
      this.tokens--;
      return true;
    }
    return false;
  }

  refill() {
    const now = Date.now();
    const elapsed = (now - this.lastRefill) / 1000;
    this.tokens = Math.min(this.capacity, this.tokens + elapsed * this.refillRate);
    this.lastRefill = now;
  }
}

Express Middleware

javascript
const rateLimit = require('express-rate-limit');

const limiter = rateLimit({
  windowMs: 15 * 60 * 1000, // 15 minutes
  max: 100,
  standardHeaders: true,
  message: { error: 'Too many requests, try again later' }
});

app.use('/api/', limiter);

Response Headers

X-RateLimit-Limit: 100
X-RateLimit-Remaining: 45
X-RateLimit-Reset: 1705320000
Retry-After: 60

Tiered Limits

TierRequests/Hour
Free100
Pro1,000
Enterprise10,000

Best Practices

  • Use Redis for distributed rate limiting
  • Include proper headers in responses
  • Return 429 status with Retry-After
  • Implement tiered limits for different plans
  • Monitor rate limit metrics
  • Test under load

© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/api-rate-limiting/skills/api-rate-limiting of secondsky/claude-skills.

Open the folder on GitHubat commit 8837836

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in secondsky/claude-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

API Rate Limiting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Rate Limiting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Rate Limiting this skillsecondsky/claude-skills2271 repos~497Automated safety check: PassMIT
Upstash Ratelimit TSupstash/ratelimit-js2.1k1 repos~313Automated safety check: PassMIT
Write API Routeryokun6/ryos1.3k—~2.1kAutomated safety check: PassAGPL-3.0
Frontmcp Configagentfront/frontmcp146—~7kAutomated safety check: PassApache-2.0
Redis Patternsaffaan-m/ECC274k1 repos~3kAutomated safety check: PassMIT
Amazon Elasticacheaws/agent-toolkit-for-aws2.8k—~4.5kAutomated safety check: PassApache-2.0

Similar skills

  • Upstash Ratelimit TS

    upstash/ratelimit-js

    Official

    Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.

    2.1k GitHub starsUsed in 1 repo~313 tokens
    Backend & APIsAuto-check passed
  • Write API Route

    ryokun6/ryos

    Create or modify ryOS backend API routes under api/ using the shared apiHandler wrapper, request-auth, Redis, rate limiting, and CORS conventions.

    1.3k GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Frontmcp Config

    agentfront/frontmcp

    A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.

    146 GitHub stars~7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Redis Patterns

    affaan-m/ECC

    Redis data structure patterns, caching strategies, distributed locks, rate limiting, pub/sub, and connection management for production applications.

    274k GitHub starsUsed in 1 repo~3k tokens
    Backend & APIsAuto-check passed
  • Amazon Elasticache

    aws/agent-toolkit-for-aws

    Official

    Activate when developers have latent caching needs: slow API responses, database read bottlenecks, DynamoDB throttling or cost, RDS/Aurora scaling pressure, Bedrock latency or cost, or adding a…

    2.8k GitHub stars~4.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • Implementing API Abuse Detection With Rate Limiting

    mukul975/Anthropic-Cybersecurity-Skills

    Implements API abuse detection using token bucket, sliding window, and fixed window rate-limiting algorithms backed by Redis, including adaptive limits that tighten during detected attacks and relax…

    34k GitHub stars~3.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from secondsky/claude-skills

All 169 skills in this repo
  • Tanstack AI

    secondsky/claude-skills

    TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.

    227 GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check: notes
  • Auto Animate

    secondsky/claude-skills

    AutoAnimate (@formkit/auto-animate) zero-config animations for React.

    227 GitHub stars~2.9k tokensUpdated 9 days ago
    Auto-check passed
  • Base UI React

    secondsky/claude-skills

    MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.

    227 GitHub stars~1.9k tokensUpdated 9 days ago
    Auto-check passed
  • Cloudflare Images

    secondsky/claude-skills

    This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…

    227 GitHub stars~3.6k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Nextjs

    secondsky/claude-skills

    Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).

    227 GitHub stars~5.3k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Sandbox

    secondsky/claude-skills

    Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.

    227 GitHub stars~4.5k tokensUpdated 9 days ago
    Auto-check passed

Works with

Categories

Questions about API Rate Limiting

What does API Rate Limiting do?

Implements API rate limiting using token bucket, sliding window, and Redis-based algorithms to protect against abuse. API Rate Limiting is an agent skill from secondsky/claude-skills. Implements API rate limiting using token bucket, sliding window, and Redis-based algorithms to protect against abuse.

When should I use API Rate Limiting?

API Rate Limiting fits situations like: securing public APIs; implementing tiered access; preventing denial-of-service attacks.

How do I install API Rate Limiting in Claude Code?

Run `npx skills add secondsky/claude-skills --skill api-rate-limiting -a claude-code`. Or copy the skill folder (plugins/api-rate-limiting/skills/api-rate-limiting in secondsky/claude-skills) into .claude/skills/api-rate-limiting in your project. Claude Code loads it when a task matches its description.

How do I install API Rate Limiting in Codex?

Run `npx skills add secondsky/claude-skills --skill api-rate-limiting -a codex`. Or copy the skill folder (plugins/api-rate-limiting/skills/api-rate-limiting in secondsky/claude-skills) into .agents/skills/api-rate-limiting in your project. Codex loads it when a task matches its description.

Can I use API Rate Limiting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill api-rate-limiting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-rate-limiting, .gemini/skills/api-rate-limiting, .github/skills/api-rate-limiting and .opencode/skills/api-rate-limiting in your project.

What does API Rate Limiting need to run?

SKILL.md names no scripts, command-line tools or credentials: API Rate Limiting is instructions for the agent only. Our summary lists: Node.js.

Does API Rate Limiting access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Rate Limiting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Rate Limiting use?

API Rate Limiting is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Rate Limiting use?

About 497 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Rate Limiting?

Skills that share tags, products or a category with API Rate Limiting: Upstash Ratelimit TS (upstash/ratelimit-js, 2.1k stars), Write API Route (ryokun6/ryos, 1.3k stars), Frontmcp Config (agentfront/frontmcp, 146 stars) and Redis Patterns (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Rate Limiting?

secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.

Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.