Upstash Ratelimit TS
upstash/ratelimit-js
Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.
Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.
$ npx skills add simstudioai/sim --skill add-hosted-key -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install simstudioai/sim add-hosted-key --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/add-hosted-key .claude/skills/add-hosted-key && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "add-hosted-key" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-hosted-key into .claude/skills/add-hosted-key/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-hosted-key", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/simstudioai/sim/tree/main/.agents/skills/add-hosted-keyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add simstudioai/sim --skill add-hosted-key -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install simstudioai/sim add-hosted-key --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/add-hosted-key .agents/skills/add-hosted-key && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "add-hosted-key" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-hosted-key into .agents/skills/add-hosted-key/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-hosted-key", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add simstudioai/sim --skill add-hosted-key -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install simstudioai/sim add-hosted-key --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/add-hosted-key .cursor/skills/add-hosted-key && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "add-hosted-key" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-hosted-key into .cursor/skills/add-hosted-key/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-hosted-key", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/simstudioai/sim.git --path .agents/skills/add-hosted-key--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add simstudioai/sim --skill add-hosted-key -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install simstudioai/sim add-hosted-key --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/add-hosted-key .gemini/skills/add-hosted-key && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "add-hosted-key" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-hosted-key into .gemini/skills/add-hosted-key/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-hosted-key", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install simstudioai/sim add-hosted-keyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add simstudioai/sim --skill add-hosted-key -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/add-hosted-key .github/skills/add-hosted-key && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "add-hosted-key" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-hosted-key into .github/skills/add-hosted-key/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-hosted-key", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add simstudioai/sim --skill add-hosted-key -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install simstudioai/sim add-hosted-key --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/add-hosted-key .opencode/skills/add-hosted-key && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "add-hosted-key" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-hosted-key into .opencode/skills/add-hosted-key/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-hosted-key", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
add-hosted-keyAdd hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.
Add Hosted Key is an agent skill from simstudioai/sim. Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own. Use when adding a hosting config to a tool under apps/sim/tools/{service}/.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Backend & APIs, covering Rate limiting. The repository describes itself as: Sim is the collaborative workspace to build, deploy, and monitor AI agents and workflows. Used by 100,000+ builders. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 546d4e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bunFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
serper.devFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Add Hosted Key loads about 3.4k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 1,367 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from simstudioai/sim at commit 546d4e7, republished under its Apache-2.0 licence (© simstudioai). 1,367 words, ~3,427 tokens.
.claude/skills/add-hosted-key/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.When a tool has hosted key support, Sim provides its own API key if the user hasn't configured one (via BYOK or env var). Usage is metered and billed to the workspace.
| Step | What | Where |
|---|---|---|
| 1 | Register BYOK provider ID | tools/types.ts, lib/api/contracts/byok-keys.ts |
| 2 | Research the API's pricing and rate limits | API docs / pricing page (before writing any code) |
| 3 | Add hosting config to the tool | tools/{service}/{action}.ts |
| 4 | Hide API key field when hosted | blocks/blocks/{service}.ts |
| 5 | Add to BYOK settings UI | BYOK settings component (byok.tsx) |
| 6 | Summarize pricing and throttling comparison | Output to user (after all code changes) |
Add the new provider to the BYOKProviderId union in tools/types.ts:
export type BYOKProviderId =
| 'openai'
| 'anthropic'
// ...existing providers
| 'your_service'Then add the same provider id to the byokProviderIdSchema enum in lib/api/contracts/byok-keys.ts (this is what the byok-keys route validates against):
export const byokProviderIdSchema = z.enum([
'openai',
'anthropic',
// ...existing providers
'your_service',
])Before writing any getCost or rateLimit code, look up the service's official documentation for both pricing and rate limits. You need to understand:
creditsUsed, costDollars, tokensUsed, or similar in the response body or headersRetry-After header, error body format, etc.Search the API's docs/pricing page (use WebSearch/WebFetch). Capture the pricing model as a comment in getCost so future maintainers know the source of truth.
Our rate limiter (lib/core/rate-limiter/hosted-key/) uses a token-bucket algorithm applied per billing actor (workspace). It supports two modes:
per_request — simple; just requestsPerMinute. Good when the API charges flat per-request or cost doesn't vary much.custom — requestsPerMinute plus additional dimensions (e.g., tokens, search_units). Each dimension has its own limitPerMinute and an extractUsage function that reads actual usage from the response. Use when the API charges on a variable metric (tokens, credits) and you want to cap that metric too.When choosing values for requestsPerMinute and any dimension limits:
N hosted keys, so the effective API-side rate per key is (total requests) / N. But per-workspace limits are enforced before key selection, so they apply regardless of key count.hosting Config to the ToolAdd a hosting object to the tool's ToolConfig. This tells the execution layer how to acquire hosted keys, calculate cost, and rate-limit.
hosting: {
envKeyPrefix: 'YOUR_SERVICE_API_KEY',
apiKeyParam: 'apiKey',
byokProviderId: 'your_service',
pricing: {
type: 'custom',
getCost: (_params, output) => {
if (output.creditsUsed == null) {
throw new Error('Response missing creditsUsed field')
}
const creditsUsed = output.creditsUsed as number
const cost = creditsUsed * 0.001 // dollars per credit
return { cost, metadata: { creditsUsed } }
},
},
rateLimit: {
mode: 'per_request',
requestsPerMinute: 100,
},
},Keys use a numbered naming pattern driven by a count env var:
YOUR_SERVICE_API_KEY_COUNT=3
YOUR_SERVICE_API_KEY_1=sk-...
YOUR_SERVICE_API_KEY_2=sk-...
YOUR_SERVICE_API_KEY_3=sk-...The envKeyPrefix value (YOUR_SERVICE_API_KEY) determines which env vars are read at runtime. Adding more keys only requires bumping the count and adding the new env var.
Always prefer using cost data returned by the API (e.g., creditsUsed, costDollars). This is the most accurate because it accounts for variable pricing tiers, feature modifiers, and plan-level discounts.
When the API reports cost — use it directly and throw if missing:
pricing: {
type: 'custom',
getCost: (params, output) => {
if (output.creditsUsed == null) {
throw new Error('Response missing creditsUsed field')
}
// $0.001 per credit — from https://example.com/pricing
const cost = (output.creditsUsed as number) * 0.001
return { cost, metadata: { creditsUsed: output.creditsUsed } }
},
},When the API does NOT report cost — compute it from params/output based on the pricing docs, but still validate the data you depend on:
pricing: {
type: 'custom',
getCost: (params, output) => {
if (!Array.isArray(output.searchResults)) {
throw new Error('Response missing searchResults, cannot determine cost')
}
// Serper: 1 credit for <=10 results, 2 credits for >10 — from https://serper.dev/pricing
const credits = Number(params.num) > 10 ? 2 : 1
return { cost: credits * 0.001, metadata: { credits } }
},
},getCost must always throw if it cannot determine cost. Never silently fall back to a default — this would hide billing inaccuracies.
If the API returns cost info, capture it in transformResponse so getCost can read it from the output:
transformResponse: async (response: Response) => {
const data = await response.json()
return {
success: true,
output: {
results: data.results,
creditsUsed: data.creditsUsed, // pass through for getCost
},
}
},For async/polling tools, capture it in postProcess when the job completes:
if (jobData.status === 'completed') {
result.output = {
data: jobData.data,
creditsUsed: jobData.creditsUsed,
}
}In the block config (blocks/blocks/{service}.ts), add hideWhenHosted: true to the API key subblock. This hides the field on hosted Sim since the platform provides the key:
{
id: 'apiKey',
title: 'API Key',
type: 'short-input',
placeholder: 'Enter your API key',
password: true,
required: true,
hideWhenHosted: true,
},The visibility is controlled by isSubBlockHidden() in lib/workflows/subblocks/visibility.ts, which checks both getDeploymentShape().hosted (hideWhenHosted) and optional env var conditions (hideWhenEnvSet).
When a block has multiple operations but some operations should not use a hosted key (e.g., the underlying API is deprecated, unsupported, or too expensive), use the duplicate apiKey subblock pattern:
hosting config from the tool definition for that operation — it must not have a hosting object at all.apiKey subblock in the block config with opposing conditions:// API Key — hidden when hosted for operations with hosted key support
{
id: 'apiKey',
title: 'API Key',
type: 'short-input',
placeholder: 'Enter your API key',
password: true,
required: true,
hideWhenHosted: true,
condition: { field: 'operation', value: 'unsupported_op', not: true },
},
// API Key — always visible for unsupported_op (no hosted key support)
{
id: 'apiKey',
title: 'API Key',
type: 'short-input',
placeholder: 'Enter your API key',
password: true,
required: true,
condition: { field: 'operation', value: 'unsupported_op' },
},Both subblocks share the same id: 'apiKey', so the same value flows to the tool. The conditions ensure only one is visible at a time. The first has hideWhenHosted: true and shows for all hosted operations; the second has no hideWhenHosted and shows only for the excluded operation — meaning users must always provide their own key for that operation.
To exclude multiple operations, use an array: { field: 'operation', value: ['op_a', 'op_b'] }.
Reference implementation: blocks/blocks/google_maps.ts — speed_limits (deprecated Roads API) is excluded from hosting with the duplicate apiKey pair.
Add an entry to the PROVIDERS array in the BYOK settings component so users can bring their own key. You need the service icon from components/icons.tsx:
{
id: 'your_service',
name: 'Your Service',
icon: YourServiceIcon,
description: 'What this service does',
placeholder: 'Enter your API key',
},Then add the id to exactly one section's ids in PROVIDER_SECTIONS (same file), and run
bun run check:byok-providers.
After all code changes are complete, output a detailed summary to the user covering:
getCost approach — how we calculate cost, what fields we depend on, and any assumptions or estimates (especially when the API doesn't report exact dollar cost).rateLimit config — what we set for requestsPerMinute (and dimensions if custom mode), why we chose those values, and how they compare to the API's limits.Present this as a structured summary with clear headings. Example:
### Pricing
- **API charges**: $X per 1M tokens (input), $Y per 1M tokens (output) — varies by model
- **Response reports cost?**: No — only token counts in `usage` field
- **Our getCost**: Estimates cost at $Z per 1M total tokens based on median model pricing
- **Risk**: Actual cost varies by model; our estimate may over/undercharge for cheap/expensive models
### Throttling
- **API limits**: 300 RPM per key (paid tier), 60 RPM (free tier)
- **Per-key or per-account**: Per key — more keys = more throughput
- **Our config**: 60 RPM per workspace (per_request mode)
- **With N keys**: Effective per-key rate is (total RPM across workspaces) / N
- **Headroom**: Comfortable — even 10 active workspaces at full rate = 600 RPM / 3 keys = 200 RPM per key, under the 300 RPM API limitThis summary helps reviewers verify that the pricing and rate limiting are well-calibrated and surfaces any risks that need monitoring.
BYOKProviderId in tools/types.tsbyokProviderIdSchema enum in lib/api/contracts/byok-keys.tshosting config added to the tool with envKeyPrefix, apiKeyParam, byokProviderId, pricing, and rateLimitgetCost throws if required cost data is missing from the responsetransformResponse or postProcess if API provides ithideWhenHosted: true added to the API key subblock in the block configPROVIDER_SECTIONS section's ids; bun run check:byok-providers passes{PREFIX}_COUNT and {PREFIX}_1..N© simstudioai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/add-hosted-key of simstudioai/sim.
Open the folder on GitHubat commit 546d4e7
Add Hosted Key next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Add Hosted Key this skillsimstudioai/sim | 30k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Upstash Ratelimit TSupstash/ratelimit-js | 2.1k | 1 repos | ~313 | Automated safety check: Pass | MIT | |
| API Gatewayitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Repo2skillzhangyanxs/repo2skill | 246 | — | ~3.6k | Automated safety check: Pass | None | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| Dload Fetch Toolphp-internal/dload | 105 | — | ~1.1k | Automated safety check: Pass | BSD-3-Clause |
upstash/ratelimit-js
Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.
itsmostafa/aws-agent-skills
AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.
zhangyanxs/repo2skill
Convert GitHub/GitLab/Gitee repositories into comprehensive OpenCode Skills using embedded LLM calls with multiple mirrors and rate limit handling
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
php-internal/dload
Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).
matrixorigin/memoria
Memoria REST API endpoints, request/response formats, auth, rate limits.
simstudioai/sim
Install, upgrade, and operate the Sim Helm chart on Kubernetes.
simstudioai/sim
Add a new table column type to Sim — registry entry, icon, storage shape, coercion, and the behavioral hooks the grid and API read.
simstudioai/sim
Add a code-defined table enrichment (registry entry) under apps/sim/enrichments/ backed by an ordered provider cascade, ensuring every provider tool it calls has hosted-key support.
simstudioai/sim
Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification…
simstudioai/sim
Add or update a Sim dynamic selector using the shared manifest, server attachment, and selectors.execute path.
simstudioai/sim
Drive a PR to a clean review (Greptile 5/5, zero open threads) — ships if needed, keeps it mergeable against staging, re-triggers both Greptile and cubic, fixes real findings, replies to and…
Categories
Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own. Add Hosted Key is an agent skill from simstudioai/sim. Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.
Add Hosted Key fits situations like: adding a hosting config to a tool under apps/sim/tools/{service}/; tasks that involve Rate limiting.
Run `npx skills add simstudioai/sim --skill add-hosted-key -a claude-code`. Or copy the skill folder (.agents/skills/add-hosted-key in simstudioai/sim) into .claude/skills/add-hosted-key in your project. Claude Code loads it when a task matches its description.
Run `npx skills add simstudioai/sim --skill add-hosted-key -a codex`. Or copy the skill folder (.agents/skills/add-hosted-key in simstudioai/sim) into .agents/skills/add-hosted-key in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add simstudioai/sim --skill add-hosted-key -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-hosted-key, .gemini/skills/add-hosted-key, .github/skills/add-hosted-key and .opencode/skills/add-hosted-key in your project.
Going by SKILL.md and its folder, Add Hosted Key needs the command-line tools its instructions call (bun). Our summary lists: A credential in YOUR_SERVICE_API_KEY.
SKILL.md names 1 domain. In commands or code: serper.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Add Hosted Key is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Add Hosted Key: Upstash Ratelimit TS (upstash/ratelimit-js, 2.1k stars), API Gateway (itsmostafa/aws-agent-skills, 1.2k stars), Repo2skill (zhangyanxs/repo2skill, 246 stars) and Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
simstudioai (a GitHub organization) maintains it in simstudioai/sim, which has 29,785 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 7, 2026.
Source: simstudioai/sim on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.