Skip to main content

High-performance async rate limiter for FastAPI with Redis or native in-memory backend

Project description

fastapi‑easylimiter

GitHub stars GitHub forks GitHub issues GitHub license PyPI

An ASGI async rate-limiting middleware for FastAPI with Redis or in-memory caching. Designed to handle auto-generated routes (such as those provided by FastAPI-Users) without requiring decorators, purely out of simplicity.

Features

  • Async rate limiting
  • Optional temporary IP bans
    • Configurable threshold (default 10 violations)
    • Sliding 30-min offense window
    • 5-min ban on repeat abuse
  • Cache
    • Redis
    • In-Memory (single worker dev)
  • Path Based Rules
  • Multi-rule prefix matching
    • Capable of global rate-limits and per-route
  • Standard rate-limit headers
    • X-RateLimit-Limit
    • X-RateLimit-Remaining
    • X-RateLimit-Reset
    • Retry-After on 429 responses
    • Tracking for remaining time sent in headers
  • Proxy Aware
    • Uses 'X-Forwarded-For' only when the sender is trusted
    • Rejects spoofed XFF headers
    • Uses 'CF-Connecting-IP' and chekcks connection IP against CF CIDR list
    • Falls back to ASGI scope["client"] if no trusted headers exist
  • Zero Dependencies Beyond Redis Client
    • Starlette-style ASGI middleware

Installation

pip install fastapi-easylimiter

Usage

from fastapi import FastAPI
from fastapi_easylimiter import AsyncRedisBackend, InMemoryBackend, RateLimiterMiddleware
import redis.asyncio as redis_async

app = FastAPI()

REDIS_URL = "redis://localhost:6379/0"

# Redis backend (recommended for multi-instance deployments)
redis_client = redis_async.from_url(REDIS_URL, decode_responses=True)
backend = AsyncRedisBackend(redis_client)

# Or for single-instance/local development:
# backend = InMemoryBackend()

rules = {
    "/": {"limit": 600, "period": 60},          # GLOBAL: 600 req/min per IP
    "/api/": {"limit": 10, "period": 1},
    "/api/users": {"limit": 1, "period": 2},
}

app.add_middleware(
    RateLimiterMiddleware,
    rules=rules,
    backend=backend,
    trusted_proxies=["127.0.0.1"],
    cloudflare=True, # enables CF-Connecting-IP
    enable_bans=True,         # ← new: turn on/off banning
    ban_threshold=15,         # ← violations before ban
    ban_duration=900,         # ← ban length in seconds
    offenses_ttl=1800,        # ← offense counting window
)

Rules are automatically sorted longest-first as seen in the code example.

A request to /api/users/me will match:

  • /api/users
  • /api

If ANY rule is exceeded → request becomes 429.

Uses Atomic LUA script:

local count = redis.call('INCR', key)
if count == 1 then redis.call('EXPIRE', key, period) end

Keys follow the pattern - rl:{client_ip}:{prefix}, which is saved as rl:203.0.113.5:/api

Parameter Type Description
app ASGIApp FastAPI/ASGI app
rules dict { prefix: {"limit": int, "period": int} }
backend Redis or InMemory backend Rate-limit storage
trusted_proxies list[str] Proxies allowed to trust XFF headers
cloudflare bool Enable Cloudflare IP extraction

Contributing

Contributions and forks are always welcome! Feel free to adapt and improve for your own needs.

Support

Buy Me a Coffee

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

fastapi_easylimiter-0.2.7.tar.gz (6.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

fastapi_easylimiter-0.2.7-py3-none-any.whl (8.2 kB view details)

Uploaded Python 3

File details

Details for the file fastapi_easylimiter-0.2.7.tar.gz.

File metadata

  • Download URL: fastapi_easylimiter-0.2.7.tar.gz
  • Upload date:
  • Size: 6.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.1

File hashes

Hashes for fastapi_easylimiter-0.2.7.tar.gz
Algorithm Hash digest
SHA256 e840e8c92c37b21639237f7bbbb662f746b63e3e53d6d316a16a97a7f43d6dc0
MD5 4c073e80482ecd0cf7df1cff1b19875d
BLAKE2b-256 743c9660ff422c0b1d5be7c1d648a22834ab17b87ecbb5d297ebf619348fa1b3

See more details on using hashes here.

File details

Details for the file fastapi_easylimiter-0.2.7-py3-none-any.whl.

File metadata

File hashes

Hashes for fastapi_easylimiter-0.2.7-py3-none-any.whl
Algorithm Hash digest
SHA256 299e6164efccc2fe46cf8197053fd22740746d80b32990911252a86369bc725b
MD5 9244eb1d2725173563e8313624c68123
BLAKE2b-256 032bfba14370d5b41ac3071d66c1b7706fc3bcbcb78bbd50c115a472c63284f0

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page