Operation Rate Limiting

PRO

Control the Frequency of
Business Operations

Apply rate limits directly to business operations with fine-grained policies, partition-aware rules, and enforcement models that fit real application workflows.

Available starting with ABP v10.3.

Trusted by the teams shaping the future of .NET

Rate limiting where it matters most in your business logic

HTTP pipeline versus application and domain specific operations

HTTP Rate limiting isn't Enough

ASP.NET Core's built-in rate limiting works at the HTTP pipeline level, great for DDoS protection and API throttling, but too coarse for business rules like "max 3 SMS codes per hour per phone number" or "max 2 report generations per day per user."

Fine-Grained Control at the Operation Level

The Operation Rate Limiting module works at the application and domain code level. Define policies for specific operations, partition counters by user, phone number, IP, tenant, or any custom key, and enforce limits exactly where your business logic runs.

How Operation Rate Limiting Works

Define a policy, check the limit, and let the module handle counter management, distributed locking, and error responses.

Operation rate limiting workflow

Two Ways to Enforce Limits

Use the declarative attribute for clean, convention-based enforcement, or inject the checker service for full programmatic control.

Declarative with [OperationRateLimiting]

Apply the attribute to Application Service methods or MVC Controller actions. The rate limit is checked automatically before the method executes, with no manual code needed.

Mark a parameter with [RateLimitingParameter] or implement IHasOperationRateLimitingParameter on your DTO to control how the partition key is resolved.

Programmatic with IOperationRateLimitingChecker

Inject the checker service and call CheckAsync, IsAllowedAsync, GetStatusAsync, or ResetAsync for full control over rate limiting behavior.

CheckAsync throws AbpOperationRateLimitingException (HTTP 429) when limits are exceeded, automatically handled by ABP's exception pipeline.

Flexible Partition Strategies

Group rate limit counters by any dimension: users, tenants, IPs, phone numbers, emails, or your own custom keys.

Built-in Partition Types

Partition by parameter (phone number, API key, etc.), current user, current tenant, client IP address, email, or phone number. Each partition type creates independent counters so different keys never interfere with each other.

Custom Partition Resolvers

Register named resolvers for complex scenarios, combine device ID with user, resolve keys from extra properties, or query a database. Resolvers are async and stored by name for easy management and replacement in downstream modules.

Operation rate limiting partition strategies

Powerful Policy Configuration

Define simple or complex rate limiting policies with multi-rule support, custom error codes, and full override capabilities.

Operation rate limiting policy configuration

Single & Multi-Rule Policies

Use a simple fixed window for straightforward limits, or combine multiple rules with AND logic. A two-phase check ensures no counter is wasted when one rule blocks the request.

Override & Customize

Replace an existing policy entirely with AddPolicy, or fine-tune it with ConfigurePolicy - add rules on top, change the error code, or clear and redefine.

Named Rules

Give rules a stable name so changing parameters like maxCount or duration won't reset existing counters. Essential when rules are managed from a database or UI.

Key Features

Enterprise-grade rate limiting with multi-tenancy, distributed caching, extensibility, and seamless ABP integration.

Multi-Tenancy Support

Multi-Tenancy Support

Enable tenant-isolated counters per rule with WithMultiTenancy(). Each tenant gets independent rate limits, or share counters globally - your choice per policy.

Distributed Cache Storage

Distributed Cache Storage

Built on ABP's IDistributedCache for production-ready distributed counter storage. Distributed locking ensures thread-safe counter increments across multiple instances.

Fully Extensible

Fully Extensible

Replace the store, implement custom rate limiting algorithms (sliding window, token bucket), customize time formatters, or load policies from a database. Every component is designed for override.

Built for Real-World Scenarios

From SMS verification to brute-force prevention, apply rate limits exactly where your application needs them.

SMS & Email Verification

Limit how often verification codes can be sent to the same phone number or email address. Prevent abuse without blocking legitimate users.

Login & Authentication Protection

Restrict login attempts per username and per IP address with multi-rule policies. Stop brute-force attacks while keeping the experience smooth for real users.

Resource-Intensive Operations

Cap expensive operations like report generation, file exports, or AI API calls per user or per tenant. Protect your infrastructure from unintentional overload.

Works Alongside ASP.NET Core Rate Limiting

Use both together - ASP.NET Core middleware for broad API protection, and this module for targeted business operation limits.

ASP.NET Core versus operation rate limiting comparison

Complementary, not competing

ASP.NET Core's built-in rate limiting operates at the HTTP request pipeline, ideal for DDoS protection and global API throttling. Operation Rate Limiting operates at the application layer, ideal for business logic constraints on specific operations.

Pre-installed with the Account (Pro) module and the latest ABP startup templates. No manual installation needed - just define your policies and start protecting your operations.

Seamlessly Integrated with ABP Platform

Built on ABP's distributed caching, dependency injection, and exception handling, and works out of the box with your existing ABP infrastructure.

ABP integration points for operation rate limiting

Zero-configuration for ABP applications

The module integrates with ABP's IDistributedCache for counter storage, ICurrentUser and ICurrentTenant for partition resolution, IWebClientInfoProvider for IP-based limits, and ABP's exception handling pipeline for automatic HTTP 429 responses.

It supports the ABP interceptor system for declarative attribute enforcement on Application Services and an ASP.NET Core action filter for MVC Controllers, all automatically registered.

Choose the Database & UI Framework That Fits Your Architecture

Operation Rate Limiting works seamlessly with ABP's supported databases and UI stacks, so you can enforce policies without changing your architectural choices.

Database Providers

All starter templates offer multiple options for implementing your data access layer.

MongoDB Entity Framework Core

Learn More About the ABP Operation Rate Limiting Module

Dive into the documentation to see every feature in detail.

Explore the Other Modules

Pro
Chat

Chat

Free
Docs

Docs

Pro
GDPR

GDPR

Pro
SaaS

SaaS

1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.