Skip to main content

Rate Limiting in Cloudflare: Capping Request Frequency

Cloudflare · 29.09.2026

Rate Limiting in Cloudflare caps the number of requests from one source over a given period. The rule is useful where a plain block does not fit: a login form, site search, an API endpoint — a legitimate user should get through, while a password-guessing script or a scraper should be denied after crossing the threshold.

The mechanism counts requests by a key — usually the IP address, but a header, cookie, or query parameter can also be used. The counter runs on Cloudflare edge servers, so the origin does not see the extra traffic even before the limit triggers.

How to create a Rate Limiting rule in the dashboard

The rule is configured under Security → WAF → Rate limiting rules. The steps are as follows.

  1. Open Rate limiting rules and click Create rule.
  2. Specify the condition for requests the limit applies to — for example, the path /api/login.
  3. Set the counting period and the request threshold.
  4. Choose the counting key: IP, IP and User-Agent, or a header value.
  5. Configure the action on overflow and the duration of the block.

Rule parameters: period, threshold, action

The table shows the main parameters and typical values for different scenarios.

ParameterExample valuePurpose
Period10 secondsRequest counting window
Threshold20 requestsMaximum per period
ActionBlock, ChallengeReaction on overflow
Mitigation timeout60 secondsDuration of the block

Rule examples for common scenarios

Below is a condition that limits login attempts from one IP address to 5 requests per 60 seconds.

(http.request.uri.path eq "/wp-login.php") and (http.request.method eq "POST")
  • Protecting a login form from password guessing without blocking regular visitors.
  • Limiting calls to a heavy search endpoint that loads the database.
  • Capping a public API key when a partner's plan limits requests per minute.

Rate Limiting versus WAF Custom Rules: which to pick

When the task is to block traffic by a fixed trait, such as a country or a path without a token, the right tool is WAF Custom Rules. Rate Limiting solves a different task: it reacts not to the content of a request but to how often the same source repeats it.

For pinpoint blocking of specific IP addresses without counting frequency, it is simpler to use Firewall rules — they apply immediately, without building up a counter.

How to test the trigger and check the logs

You can test a rule with a series of repeated requests over curl — after the threshold is crossed, the server should return code 429 or a challenge page.

for i in $(seq 1 10); do curl -s -o /dev/null -w "%{http_code}\n" https://example.com/wp-login.php; done

Trigger events appear in Security → Events with the counting key and IP address shown. The overall dynamics of blocked requests are easy to see in Cloudflare Analytics.

Checklist before enabling the rule

  • The condition limits exactly the needed path, not the whole site.
  • The threshold and period were checked against real load, not guessed.
  • The counting key accounts for a shared IP among users behind NAT or a CDN.
  • The action on overflow does not block legitimate integrations forever.
  • After enabling, the reaction to a series of test requests was verified.
← Back to Knowledge Base Ask Support