Agent skill

Upstash Ratelimit

by sickn33 in sickn33/agentic-awesome-skills

Add rate limiting to API routes, middleware, and edge functions with @upstash/ratelimit: sliding window, fixed window, and token bucket backed by Upstash Redis.

MITAuto-check passedBackend & APIs

Install Upstash Ratelimit

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill upstash-ratelimit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills upstash-ratelimit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/upstash-ratelimit .claude/skills/upstash-ratelimit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upstash-ratelimit
GitHub stars
47k
Used in
1 other repo
Token cost
~1.7k tokens
SKILL.md length
616 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Add rate limiting to API routes, middleware, and edge functions with @upstash/ratelimit: sliding window, fixed window, and token bucket backed by Upstash Redis.

  • Works in 3 steps: Install and configure → Create the limiter once, outside the… → Call limit() with a stable identifier
  • Tasks that involve Rate limiting
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Examples, plus 6 more sections
  • Calls npm; needs UPSTASH_REDIS_REST_TOKEN

What it does

Upstash Ratelimit is an agent skill from sickn33/agentic-awesome-skills. Add rate limiting to API routes, middleware, and edge functions with @upstash/ratelimit: sliding window, fixed window, and token bucket backed by Upstash Redis.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Rate limiting and Serverless. It works with Upstash and Redis. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Rate limiting
  • Tasks that involve Serverless

Example prompts

  • “/upstash-ratelimit”

Requirements

  • Node.js
  • A credential in UPSTASH_REDIS_REST_TOKEN

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Install and configure
  2. Create the limiter once, outside the handler
  3. Call limit() with a stable identifier

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • upstash.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • UPSTASH_REDIS_REST_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Upstash Ratelimit loads about 1.7k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 616 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 616 words, ~1,683 tokens.

Download SKILL.mdSave it as .claude/skills/upstash-ratelimit/SKILL.md (or your agent's skills folder).
name
upstash-ratelimit
description
Add rate limiting to API routes, middleware, and edge functions with @upstash/ratelimit: sliding window, fixed window, and token bucket backed by Upstash Redis.
category
backend
risk
critical
source
self
source_type
self
date_added
2026-08-31
author
CahidArda
tags
upstash, rate-limiting, redis, serverless, edge, middleware, 429
tools
claude, codex, cursor, gemini

Upstash Ratelimit

Overview

@upstash/ratelimit implements distributed rate limiting on top of Upstash Redis. Because state lives in Redis, every instance of a serverless function or edge worker shares the same counters, which an in-memory limiter cannot do. It ships three algorithms (fixed window, sliding window, token bucket), per-identifier keys, optional in-memory blocking of already-limited identifiers, and optional analytics.

When to Use This Skill

  • Use when the user needs to limit requests per IP, user, API key, or tenant across multiple serverless instances or regions.
  • Use when protecting login, signup, form, webhook, or LLM endpoints from abuse and returning 429 Too Many Requests.
  • Use when choosing between fixed window, sliding window, and token bucket.
  • Do not use for client-side retry/backoff against a third-party API's limits; see api-rate-limit-handler.
  • Do not use for a single long-running process with no shared state; an in-memory limiter is simpler there.

How It Works

Step 1: Install and configure
bash
npm install @upstash/ratelimit @upstash/redis

Set UPSTASH_REDIS_REST_URL and UPSTASH_REDIS_REST_TOKEN in the environment.

Step 2: Create the limiter once, outside the handler
typescript
import { Ratelimit } from "@upstash/ratelimit";
import { Redis } from "@upstash/redis";

export const ratelimit = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.slidingWindow(10, "10 s"), // 10 requests per 10 seconds
  prefix: "rl:api",
  analytics: true,
});

Constructing the limiter at module scope lets the built-in ephemeral cache short-circuit blocked identifiers without a Redis call.

Step 3: Call limit() with a stable identifier
typescript
const { success, limit, remaining, reset, pending } = await ratelimit.limit(userId);

success is false when the identifier is over its limit. reset is a Unix timestamp in milliseconds. pending is a promise for background work (analytics, multi-region sync); await it or pass it to waitUntil on edge runtimes so the function is not frozen before it completes.

Examples

Example 1: Next.js middleware returning 429
typescript
import { Ratelimit } from "@upstash/ratelimit";
import { Redis } from "@upstash/redis";
import { NextResponse, type NextRequest } from "next/server";

const ratelimit = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.slidingWindow(20, "1 m"),
});

export async function middleware(request: NextRequest) {
  const ip = request.headers.get("x-forwarded-for") ?? "anonymous";
  const { success, limit, remaining, reset } = await ratelimit.limit(ip);

  if (!success) {
    return new NextResponse("Too Many Requests", {
      status: 429,
      headers: {
        "X-RateLimit-Limit": String(limit),
        "X-RateLimit-Remaining": String(remaining),
        "X-RateLimit-Reset": String(reset),
        "Retry-After": String(Math.ceil((reset - Date.now()) / 1000)),
      },
    });
  }
  return NextResponse.next();
}

export const config = { matcher: "/api/:path*" };
Example 2: Token bucket with per-plan limits
typescript
const limiters = {
  free: new Ratelimit({
    redis: Redis.fromEnv(),
    prefix: "rl:free",
    limiter: Ratelimit.tokenBucket(5, "10 s", 10), // refill 5 per 10 s, burst 10
  }),
  pro: new Ratelimit({
    redis: Redis.fromEnv(),
    prefix: "rl:pro",
    limiter: Ratelimit.tokenBucket(50, "10 s", 100),
  }),
};

const { success } = await limiters[plan].limit(apiKey);

Best Practices

  • ✅ Use a stable, low-cardinality identifier (user id, API key, tenant) where possible; fall back to IP only for anonymous traffic.
  • ✅ Set a distinct prefix per endpoint or plan so limits do not collide.
  • ✅ Return Retry-After and X-RateLimit-* headers with 429 responses.
  • ✅ Prefer slidingWindow for most APIs; use tokenBucket when short bursts are acceptable; use fixedWindow when the lowest Redis cost matters.
  • ❌ Don't construct a new Ratelimit inside the request handler.
  • ❌ Don't rely on pending completing on its own in edge runtimes.
  • ❌ Don't rate limit by x-forwarded-for without validating it is set by your proxy; clients can spoof it otherwise.
Show full SKILL.md (261 more words)Show less

Limitations

  • Requires an Upstash Redis database; it does not work with other Redis servers or without network access.
  • Each limit() call is at least one HTTP round trip to Redis, so it adds latency to every request it guards.
  • Sliding window is an approximation that assumes an even spread of requests in the previous window; it is not an exact log.
  • MultiRegionRatelimit trades strict accuracy for lower latency and does not support the token bucket algorithm.
  • If Redis is unreachable, the default timeout (5 s) lets requests through (reason: "timeout"); this fails open, not closed.
  • This skill does not replace environment-specific validation, testing, or expert review.

Security & Safety Notes

  • Rate limiting is one layer of abuse protection, not authentication. Pair it with auth and input validation.
  • The Redis token grants full database access; keep it server-side.
  • Changing limits in production can lock out legitimate users. Confirm the numbers with the user before deploying stricter limits.

Common Pitfalls

  • Problem: Every request is allowed even after the limit. Solution: Each identifier must be the same string across requests; check that the identifier is not undefined or a fresh random value.
  • Problem: Analytics are empty on Vercel Edge or Cloudflare Workers. Solution: Pass pending to waitUntil (ctx.waitUntil(pending)) so the background request is not cancelled when the response is sent.
  • @upstash-redis - The client this package uses for storage.
  • @api-rate-limit-handler - Client-side backoff and retry when you are the one being rate limited.
  • @upstash-qstash - Queue and smooth traffic to downstream services instead of rejecting it.

Additional Resources

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/upstash-ratelimit of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Upstash Ratelimit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Upstash Ratelimit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Upstash Ratelimit this skillsickn33/agentic-awesome-skills47k1 repos~1.7kAutomated safety check: PassMIT
Upstash Redisgithub/awesome-copilot40k—~1.7kAutomated safety check: PassMIT
Upstash Ratelimit TSupstash/ratelimit-js2k—~313Automated safety check: PassMIT
Write API Routeryokun6/ryos1.3k—~2.1kAutomated safety check: PassAGPL-3.0
Amazon Elasticacheaws/agent-toolkit-for-aws2.8k—~4.5kAutomated safety check: PassApache-2.0
Redisericrisco/rsc-harness180—~4.3kAutomated safety check: PassMIT

Similar skills

  • Upstash Redis

    github/awesome-copilot

    Official

    Use Redis over HTTP from serverless and edge runtimes with @upstash/redis, and add rate limiting with @upstash/ratelimit.

    40k GitHub stars~1.7k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Upstash Ratelimit TS

    upstash/ratelimit-js

    Official

    Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.

    2k GitHub stars~313 tokensUpdated 14 days ago
    Backend & APIsAuto-check passed
  • Write API Route

    ryokun6/ryos

    Create or modify ryOS backend API routes under api/ using the shared apiHandler wrapper, request-auth, Redis, rate limiting, and CORS conventions.

    1.3k GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Amazon Elasticache

    aws/agent-toolkit-for-aws

    Official

    Activate when developers have latent caching needs: slow API responses, database read bottlenecks, DynamoDB throttling or cost, RDS/Aurora scaling pressure, Bedrock latency or cost, or adding a…

    2.8k GitHub stars~4.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • Redis

    ericrisco/rsc-harness

    A skill your agent uses when using Redis or any Redis-protocol store (Valkey, ElastiCache, Upstash, Dragonfly, Memorystore) as a cache, queue, rate limiter or distributed lock and it has to be…

    180 GitHub stars~4.3k tokensUpdated today
    DatabasesAuto-check passed
  • Qstash JS

    upstash/qstash-js

    Official

    Work with the QStash JavaScript/TypeScript SDK for serverless messaging, scheduling.

    269 GitHub stars~746 tokensUpdated 3 days ago
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Categories

Questions about Upstash Ratelimit

What does Upstash Ratelimit do?

Add rate limiting to API routes, middleware, and edge functions with @upstash/ratelimit: sliding window, fixed window, and token bucket backed by Upstash Redis. Upstash Ratelimit is an agent skill from sickn33/agentic-awesome-skills. Add rate limiting to API routes, middleware, and edge functions with @upstash/ratelimit: sliding window, fixed window, and token bucket backed by Upstash Redis.

When should I use Upstash Ratelimit?

Upstash Ratelimit fits situations like: tasks that involve Rate limiting; tasks that involve Serverless.

How do I install Upstash Ratelimit in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill upstash-ratelimit -a claude-code`. Or copy the skill folder (skills/upstash-ratelimit in sickn33/agentic-awesome-skills) into .claude/skills/upstash-ratelimit in your project. Claude Code loads it when a task matches its description.

How do I install Upstash Ratelimit in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill upstash-ratelimit -a codex`. Or copy the skill folder (skills/upstash-ratelimit in sickn33/agentic-awesome-skills) into .agents/skills/upstash-ratelimit in your project. Codex loads it when a task matches its description.

Can I use Upstash Ratelimit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill upstash-ratelimit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upstash-ratelimit, .gemini/skills/upstash-ratelimit, .github/skills/upstash-ratelimit and .opencode/skills/upstash-ratelimit in your project.

What does Upstash Ratelimit need to run?

Going by SKILL.md and its folder, Upstash Ratelimit needs the command-line tools its instructions call (npm) and credentials named UPSTASH_REDIS_REST_TOKEN. Our summary lists: Node.js; A credential in UPSTASH_REDIS_REST_TOKEN.

Does Upstash Ratelimit access the network?

SKILL.md names 2 domains. As links in the text: upstash.com and github.com. This is read from the text; nothing was executed.

Is Upstash Ratelimit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Upstash Ratelimit use?

Upstash Ratelimit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Upstash Ratelimit use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Upstash Ratelimit?

Skills that share tags, products or a category with Upstash Ratelimit: Upstash Redis (github/awesome-copilot, 40k stars), Upstash Ratelimit TS (upstash/ratelimit-js, 2k stars), Write API Route (ryokun6/ryos, 1.3k stars) and Amazon Elasticache (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Upstash Ratelimit?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.