Skip to main content

A flexible and efficient rate limiting library for Django applications

Project description

Django Smart Ratelimit

CI PyPI version Downloads Python Versions Django Versions License

A high-performance rate limiting library for Django. Protects your APIs from abuse with atomic Redis operations, multiple algorithms, circuit breaking, and full async support -- optimized for distributed systems.

Key Features

  • Sync and Async -- Dual-mode support with native @ratelimit and @aratelimit decorators
  • Enterprise Reliability -- Built-in circuit breaker, automatic failover, and fail-open strategies
  • Multiple Algorithms -- Token bucket, sliding window, fixed window, and leaky bucket
  • Flexible Backends -- Redis (recommended), async Redis, in-memory, MongoDB, Django ORM (database), or custom backends
  • Precise Control -- Rate limit by IP, user, header, or any custom callable
  • Shadow Mode -- Evaluate and log decisions without enforcing them for safe, zero-risk rollouts (docs)
  • Cost-Based (Weighted) Limiting -- Charge expensive requests more of the budget via a per-request cost (docs)
  • CIDR Allow/Deny Lists -- IPv4/IPv6 allowlists and denylists from inline CIDRs, files, or URL feeds (docs)
  • DRF Throttle Adapter -- Drop-in BaseThrottle classes for Django REST Framework (docs)
  • Observability -- Prometheus /metrics, OpenTelemetry spans and metrics, and structured JSON logging (docs)
  • Type-Safe Enums -- Optional Algorithm and RateLimitKey enums for autocomplete and typo-proof config
  • Configurable Proxy Trust -- RATELIMIT_TRUSTED_PROXIES for spoof-resistant client IP extraction behind load balancers (new in v3.1)
  • Adaptive Rate Limiting -- Dynamic limits based on CPU, memory, latency, and custom load indicators

Quick Start

Installation

pip install django-smart-ratelimit[redis]

Basic Usage

from django_smart_ratelimit import ratelimit

@ratelimit(key='ip', rate='5/m', block=True)
def login_view(request):
    return authenticate(request)

Keys and algorithms accept plain strings, or the RateLimitKey and Algorithm enums if you prefer autocomplete and a typo-proof contract. The two are interchangeable:

from django_smart_ratelimit import ratelimit
from django_smart_ratelimit.enums import Algorithm, RateLimitKey

@ratelimit(key=RateLimitKey.USER_OR_IP, rate='5/m', algorithm=Algorithm.TOKEN_BUCKET)
def login_view(request):
    return authenticate(request)

Async Support

from django_smart_ratelimit import aratelimit

@aratelimit(key='user', rate='100/h', block=True)
async def api_view(request):
    return await process(request)

Class-Based Views

Apply the decorator to a method with Django's method_decorator:

from django.utils.decorators import method_decorator
from django.views import View

from django_smart_ratelimit import ratelimit


class LoginView(View):
    @method_decorator(ratelimit(key='ip', rate='5/m', block=True))
    def post(self, request):
        return authenticate(request)

Configuration

Add to your Django settings:

RATELIMIT_BACKEND = 'redis'
RATELIMIT_REDIS = {'host': 'localhost', 'port': 6379, 'db': 0}
# Or point at a Redis URL instead of host/port:
# RATELIMIT_REDIS = {'url': 'redis://localhost:6379/0'}

# Optional: enable structured logging
RATELIMIT_LOGGING = {
    'ENABLED': True,
    'FORMAT': 'json',  # "json" or "text"
}

# Optional: enable Prometheus metrics
RATELIMIT_PROMETHEUS = {
    'ENABLED': True,
}

If RATELIMIT_BACKEND is unset, the in-memory backend is used by default.

Documentation

Full documentation is hosted on Read the Docs:

Topic Description
Full Documentation Start here for the complete guide
Installation Optional extras: Redis, MongoDB, DRF, Prometheus, OpenTelemetry
Decorator API Every argument, including shadow mode and cost-based limiting
Migration Guide Steps for upgrading from django-ratelimit
Algorithms Deep dive into token bucket, sliding window, and more
Backends Redis, async Redis, memory, MongoDB, and the Django ORM database backend
Configuration Advanced settings, CIDR lists, proxy trust, and circuit breakers
Deployment Running in production behind proxies and load balancers
Design Philosophy Architecture decisions and comparison with alternatives

Compatibility

Supported Versions
Python 3.9, 3.10, 3.11, 3.12, 3.13
Django 3.2, 4.0, 4.1, 4.2, 5.0, 5.1

Contributing

Contributions are welcome. Please see CONTRIBUTING.md for details on how to submit pull requests, report issues, and set up your development environment.

Community and Support

Sponsors

Support the ongoing development of Django Smart Ratelimit:

Sponsor

License

This project is licensed under the MIT License. See the LICENSE file for details.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

django_smart_ratelimit-4.0.2.tar.gz (416.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

django_smart_ratelimit-4.0.2-py3-none-any.whl (173.8 kB view details)

Uploaded Python 3

File details

Details for the file django_smart_ratelimit-4.0.2.tar.gz.

File metadata

  • Download URL: django_smart_ratelimit-4.0.2.tar.gz
  • Upload date:
  • Size: 416.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for django_smart_ratelimit-4.0.2.tar.gz
Algorithm Hash digest
SHA256 1fdc8fa60107e625fce94b085d92032ec172c0ac64bc7ef8688792d93584ab0d
MD5 f019829453bc66051b198e9575e4cf5c
BLAKE2b-256 8a2645d4c3a14b9bbb06b1c7d70ec64fba71e1b12459548bfd7c69810c72f0fc

See more details on using hashes here.

File details

Details for the file django_smart_ratelimit-4.0.2-py3-none-any.whl.

File metadata

File hashes

Hashes for django_smart_ratelimit-4.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 83b75212cee0a225b5be330f807ca6b3af0293b344b1d641d1fc4615c9fa879b
MD5 ecb8e89752ec5afbe6b2ccfeefa3aace
BLAKE2b-256 6ef0bccbe7090045cef26aea10d2ce7c7d52e21fefd41c2d611a06d390ceeb38

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page