Skip to content
OpenAppPhysical access, simplified
Login

Rate limit

Type
rate_limit
Category
Agent safety
Enforced at
Access-time
Tiers
OrgIntegration
Enforcement
Enforce
Default
Not configured — no policy throttle on opens.

Caps how many opens a principal may perform in a sliding window. Use this so a looping agent or script cannot hammer a door. Supply per_user and/or per_org as a positive integer.

When it is enforced

Evaluated when someone opens a door or gate or triggers an entity action. If this policy applies, the open is denied even when roles and grants would otherwise allow it.

Where to set it

Settings → Policies (org) or the integration Policies tab.

Policies never grant access. See thepolicies architecture guidefor how org, integration, and device tiers combine.

Arguments

The config object on create/update. Shared row fieldsenforcement (enforce, require_approval,audit_only) and enabled apply to every type;audit_only and disabled rows never block.

NameTypeRequiredValuesDescription
per_userintegerNoMaximum opens per principal in the window. At least one of per_user or per_org must be an integer greater than 0.
per_orgintegerNoMaximum opens per organization in the window. Alternative to per_user.
window_secondsintegerYesSliding window length in seconds. Required; integer from 1 through 31536000 (365 days).
applies_tostring or string[]No
agentapi_keyinvitationmemberresidentadminall
Principal kinds this row binds. Closed set: agent, api_key, invitation, member, resident, admin, all. Unknown strings and empty arrays are rejected. `all` matches every kind. When omitted, the type-specific default applies (see Default). Device-tier rows without `applies_to` often bind everyone, including admins. Default: agent, api_key, invitation
outputstring or integerNoOptional channel or output id. When set, the policy binds only that output. When omitted, it binds every output of the tier target. A scoped row does not apply when the acting output is unknown.

How overlapping rows combine

Most-restrictive (minimum) numeric caps across applicable rows.

Example

An agent that retries an open more than 30 times in a minute is denied further opens until the window slides.

config
{
"per_user": 30,
"window_seconds": 60,
"applies_to": [
"agent",
"api_key",
"invitation"
]
}

Integrations

This type is documented on these connectors: