Rate Limiting in Cloudflare caps the number of requests from one source over a given period. The rule is useful where a plain block does not fit: a login form, site search, an API endpoint — a legitimate user should get through, while a password-guessing script or a scraper should be denied after crossing the threshold.
The mechanism counts requests by a key — usually the IP address, but a header, cookie, or query parameter can also be used. The counter runs on Cloudflare edge servers, so the origin does not see the extra traffic even before the limit triggers.
How to create a Rate Limiting rule in the dashboard
The rule is configured under Security → WAF → Rate limiting rules. The steps are as follows.
- Open Rate limiting rules and click Create rule.
- Specify the condition for requests the limit applies to — for example, the path /api/login.
- Set the counting period and the request threshold.
- Choose the counting key: IP, IP and User-Agent, or a header value.
- Configure the action on overflow and the duration of the block.
Rule parameters: period, threshold, action
The table shows the main parameters and typical values for different scenarios.
| Parameter | Example value | Purpose |
|---|---|---|
| Period | 10 seconds | Request counting window |
| Threshold | 20 requests | Maximum per period |
| Action | Block, Challenge | Reaction on overflow |
| Mitigation timeout | 60 seconds | Duration of the block |
Rule examples for common scenarios
Below is a condition that limits login attempts from one IP address to 5 requests per 60 seconds.
(http.request.uri.path eq "/wp-login.php") and (http.request.method eq "POST")- Protecting a login form from password guessing without blocking regular visitors.
- Limiting calls to a heavy search endpoint that loads the database.
- Capping a public API key when a partner's plan limits requests per minute.
Rate Limiting versus WAF Custom Rules: which to pick
When the task is to block traffic by a fixed trait, such as a country or a path without a token, the right tool is WAF Custom Rules. Rate Limiting solves a different task: it reacts not to the content of a request but to how often the same source repeats it.
For pinpoint blocking of specific IP addresses without counting frequency, it is simpler to use Firewall rules — they apply immediately, without building up a counter.
How to test the trigger and check the logs
You can test a rule with a series of repeated requests over curl — after the threshold is crossed, the server should return code 429 or a challenge page.
for i in $(seq 1 10); do curl -s -o /dev/null -w "%{http_code}\n" https://example.com/wp-login.php; doneTrigger events appear in Security → Events with the counting key and IP address shown. The overall dynamics of blocked requests are easy to see in Cloudflare Analytics.
Checklist before enabling the rule
- The condition limits exactly the needed path, not the whole site.
- The threshold and period were checked against real load, not guessed.
- The counting key accounts for a shared IP among users behind NAT or a CDN.
- The action on overflow does not block legitimate integrations forever.
- After enabling, the reaction to a series of test requests was verified.