Skip to main content

docs ci codecov pypi license

Flask-Limiter provides rate limiting features to flask applications.

It has support for a configurable backend for storage with current implementations for in-memory, redis and memcache.

Compatibility

The version of the extension on master only supports Pythons versions >= 3.7 and Flask >= 2.0. If you are looking for support for older versions, please refer to the 1.x branch

Quickstart

Add the rate limiter to your flask app. The following example uses the default in memory implementation for storage.

from flask import Flask
from flask_limiter import Limiter
from flask_limiter.util import get_remote_address

app = Flask(__name__)
limiter = Limiter(
    app,
    key_func=get_remote_address,
    default_limits=["2 per minute", "1 per second"],
)

@app.route("/slow")
@limiter.limit("1 per day")
def slow():
    return "24"

@app.route("/fast")
def fast():
    return "42"

@app.route("/ping")
@limiter.exempt
def ping():
    return 'PONG'

app.run()

Test it out. The fast endpoint respects the default rate limit while the slow endpoint uses the decorated one. ping has no rate limit associated with it.

$ curl localhost:5000/fast
42
$ curl localhost:5000/fast
42
$ curl localhost:5000/fast
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<title>429 Too Many Requests</title>
<h1>Too Many Requests</h1>
<p>2 per 1 minute</p>
$ curl localhost:5000/slow
24
$ curl localhost:5000/slow
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<title>429 Too Many Requests</title>
<h1>Too Many Requests</h1>
<p>1 per 1 day</p>
$ curl localhost:5000/ping
PONG
$ curl localhost:5000/ping
PONG
$ curl localhost:5000/ping
PONG
$ curl localhost:5000/ping
PONG

Read the docs .. :changelog:

Changelog

v2.0.2

Release Date: 2021-11-28

  • Features

    • Pin Flask, limits to >= 2

    • Add type hints

v2.0.1

Release Date: 2021-11-28

  • Deprecations

    • Remove deprecated get_ipaddr method

    • Remove use of six

    • Remove backward compatibility hacks for RateLimit exceptions

v2.0.0

Release Date: 2021-11-27

Drop support for python < 3.7 & Flask < 2.0

v1.5

Release Date: 2021-11-27

Final Release for python < 3.7

  • Features

    • Prepend key_prefix to extension variables attached to g

    • Expose g.view_limits

v1.4

Release Date: 2020-08-25

  • Bug Fix

    • Always set headers for conditional limits

    • Skip init_app sequence when the rate limiter is disabled

v1.3.1

Release Date: 2020-05-21

  • Bug Fix

    • Ensure headers provided explictely by setting _header_mapping take precedence over configuration values.

v1.3

Release Date: 2020-05-20

  • Features

    • Add new deduct_when argument that accepts a function to decorated limits to conditionally perform depletion of a rate limit (Pull Request 248)

    • Add new default_limits_deduct_when argument to Limiter constructor to conditionally perform depletion of default rate limits

    • Add default_limits_exempt_when argument that accepts a function to allow skipping the default limits in the before_request phase

  • Bug Fix

    • Fix handling of storage failures during after_request phase.

  • Code Quality

    • Use github-actions instead of travis for CI

    • Use pytest instaad of nosetests

    • Add docker configuration for test dependencies

    • Increase code coverage to 100%

    • Ensure pyflake8 compliance

v1.2.1

Release Date: 2020-02-26

  • Bug fix

    • Syntax error in version 1.2.0 when application limits are provided through configuration file (Issue 241)

v1.2.0

Release Date: 2020-02-25

  • Add override_defaults argument to decorated limits to allow combinined defaults with decorated limits.

  • Add configuration parameter RATELIMIT_DEFAULTS_PER_METHOD to control whether defaults are applied per method.

  • Add support for in memory fallback without override (Pull Request 236)

  • Bug fix

    • Ensure defaults are enforced when decorated limits are skipped (Issue 238)

v1.1.0

Release Date: 2019-10-02

v1.0.1

Release Date: 2017-12-08

  • Bug fix

    • Duplicate rate limits applied via application limits (Issue 108)

v1.0.0

Release Date: 2017-11-06

  • Improved documentation for handling ip addresses for applications behind proxiues (Issue 41)

  • Execute rate limits for decorated routes in decorator instead of before_request (Issue 67)

  • Bug Fix

    • Python 3.5 Errors (Issue 82)

    • RATELIMIT_KEY_PREFIX configuration constant not used (Issue 88)

    • Can’t use dynamic limit in default_limits (Issue 94)

    • Retry-After header always zero when using key prefix (Issue 99)

v0.9.5.1

Release Date: 2017-08-18

  • Upgrade versioneer

v0.9.5

Release Date: 2017-07-26

  • Add support for key prefixes

v0.9.4

Release Date: 2017-05-01

  • Implemented application wide shared limits

v0.9.3

Release Date: 2016-03-14

  • Allow reset of limiter storage if available

v0.9.2

Release Date: 2016-03-04

  • Deprecation warning for default key_func get_ipaddr

  • Support for Retry-After header

v0.9.1

Release Date: 2015-11-21

  • Re-expose enabled property on Limiter instance.

v0.9

Release Date: 2015-11-13

  • In-memory fallback option for unresponsive storage

  • Rate limit exemption option per limit

v0.8.5

Release Date: 2015-10-05

  • Bug fix for reported issues of missing (limits) dependency upon installation.

v0.8.4

Release Date: 2015-10-03

  • Documentation tweaks.

v0.8.2

Release Date: 2015-09-17

  • Remove outdated files from egg

v0.8.1

Release Date: 2015-08-06

  • Fixed compatibility with latest version of Flask-Restful

v0.8

Release Date: 2015-06-07

  • No functional change

v0.7.9

Release Date: 2015-04-02

  • Bug fix for case sensitive methods whitelist for limits decorator

v0.7.8

Release Date: 2015-03-20

  • Hotfix for dynamic limits with blueprints

  • Undocumented feature to pass storage options to underlying storage backend.

v0.7.6

Release Date: 2015-03-02

  • methods keyword argument for limits decorator to specify specific http methods to apply the rate limit to.

v0.7.5

Release Date: 2015-02-16

v0.7.4

Release Date: 2015-02-03

  • Use Werkzeug TooManyRequests as the exception raised when available.

v0.7.3

Release Date: 2015-01-30

  • Bug Fix

    • Fix for version comparison when monkey patching Werkzeug

      (Issue 24)

v0.7.1

Release Date: 2015-01-09

  • Refactor core storage & ratelimiting strategy out into the limits package.

  • Remove duplicate hits when stacked rate limits are in use and a rate limit is hit.

v0.7

Release Date: 2015-01-09

  • Refactoring of RedisStorage for extensibility (Issue 18)

  • Bug fix: Correct default setting for enabling rate limit headers. (Issue 22)

v0.6.6

Release Date: 2014-10-21

  • Bug fix

    • Fix for responses slower than rate limiting window. (Issue 17.)

v0.6.5

Release Date: 2014-10-01

  • Bug fix: in memory storage thread safety

v0.6.4

Release Date: 2014-08-31

  • Support for manually triggering rate limit check

v0.6.3

Release Date: 2014-08-26

  • Header name overrides

v0.6.2

Release Date: 2014-07-13

v0.6.1

Release Date: 2014-07-11

  • per http method rate limit separation (Recipe)

  • documentation improvements

v0.6

Release Date: 2014-06-24

v0.5

Release Date: 2014-06-13

v0.4.4

Release Date: 2014-06-13

  • Bug fix

    • Werkzeug < 0.9 Compatibility (Issue 6.)

v0.4.3

Release Date: 2014-06-12

  • Hotfix : use HTTPException instead of abort to play well with other extensions.

v0.4.2

Release Date: 2014-06-12

  • Allow configuration overrides via extension constructor

v0.4.1

Release Date: 2014-06-04

  • Improved implementation of moving-window X-RateLimit-Reset value.

v0.4

Release Date: 2014-05-28

v0.3.2

Release Date: 2014-05-26

  • Bug fix

    • Memory leak when using Limiter.storage.MemoryStorage (Issue 4.)

  • Improved test coverage

v0.3.1

Release Date: 2014-02-20

  • Strict version requirement on six

  • documentation tweaks

v0.3.0

Release Date: 2014-02-19

  • improved logging support for multiple handlers

  • allow callables to be passed to Limiter.limit decorator to dynamically load rate limit strings.

  • add a global kill switch in flask config for all rate limits.

  • Bug fixes

    • default key function for rate limit domain wasn’t accounting for X-Forwarded-For header.

v0.2.2

Release Date: 2014-02-18

  • add new decorator to exempt routes from limiting.

  • Bug fixes

    • versioneer.py wasn’t included in manifest.

    • configuration string for strategy was out of sync with docs.

v0.2.1

Release Date: 2014-02-15

  • python 2.6 support via counter backport

  • source docs.

v0.2

Release Date: 2014-02-15

  • Implemented configurable strategies for rate limiting.

  • Bug fixes

    • better locking for in-memory storage

    • multi threading support for memcached storage

v0.1.1

Release Date: 2014-02-14

  • Bug fixes

    • fix initializing the extension without an app

    • don’t rate limit static files

v0.1.0

Release Date: 2014-02-13

  • first release.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Flask-Limiter-2.0.2.tar.gz (97.5 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

Flask_Limiter-2.0.2-py3.9.egg (28.1 kB view details)

Uploaded Egg

Flask_Limiter-2.0.2-py3-none-any.whl (15.6 kB view details)

Uploaded Python 3

File details

Details for the file Flask-Limiter-2.0.2.tar.gz.

File metadata

  • Download URL: Flask-Limiter-2.0.2.tar.gz
  • Upload date:
  • Size: 97.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.6.0 importlib_metadata/4.8.2 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.6

File hashes

Hashes for Flask-Limiter-2.0.2.tar.gz
Algorithm Hash digest
SHA256 7d83bb26510355409fd10f4d8fbc4b4bf6b177063f1a4ee70003f30f3288c430
MD5 b54052240f76bf85e91326b90c0eefaa
BLAKE2b-256 f5640f7e3a7183452946bb1b24f4045c4d07301ac61a8ee20f4e7c6cd603aebe

See more details on using hashes here.

File details

Details for the file Flask_Limiter-2.0.2-py3.9.egg.

File metadata

  • Download URL: Flask_Limiter-2.0.2-py3.9.egg
  • Upload date:
  • Size: 28.1 kB
  • Tags: Egg
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.6.0 importlib_metadata/4.8.2 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.6

File hashes

Hashes for Flask_Limiter-2.0.2-py3.9.egg
Algorithm Hash digest
SHA256 15983c500f9ab739bb0ef6b91114d2243a9dece7acf2f2a0d627bed66224e0b2
MD5 1730a77a1885e9e93e9b7de0352d988f
BLAKE2b-256 329ce258eb082357a62277aaabfd15277d9385224fd1858344aebed885e40c25

See more details on using hashes here.

File details

Details for the file Flask_Limiter-2.0.2-py3-none-any.whl.

File metadata

  • Download URL: Flask_Limiter-2.0.2-py3-none-any.whl
  • Upload date:
  • Size: 15.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.6.0 importlib_metadata/4.8.2 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.6

File hashes

Hashes for Flask_Limiter-2.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 5f3c4e70f46e60979665542ca97c35a2b2ff6f5aa27e144bf478800d4a4ad31d
MD5 263cb1b33488f7ff478ab72e44455da0
BLAKE2b-256 0f19359758886711283d246df1a0d2d0053fad413c4e93a304dc41d227901e51

See more details on using hashes here.

Release history Release notifications | RSS feed

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page