---
title: "Rate Limit Reference"
description: "Sources: `docs/security-kernel-rate-limit-ledger.json`."
engineVersion: v1.0.234
date: 2026-09-28
license: "(c) Gessa, proprietary. Cite with attribution to https://gessa.ai/docs/. Terms: https://gessa.ai/terms/."
canonical: https://gessa.ai/docs/spec/generated/rate-limits/
---
<!-- GENERATED FILE: do not edit by hand. -->
<!-- Regenerate with `npm run gen-docs`. -->

Sources: `docs/security-kernel-rate-limit-ledger.json`.

# Rate Limit Reference

This generated snapshot is derived from the security-kernel rate-limit ledger (`docs/security-kernel-rate-limit-ledger.json`, projected from `server/src/modules/security-kernel/rateLimiter.ts`). Each row is one rate-limit category applied to HTTP routes by the security kernel; the route reference names the category each operation carries in its Rate limit column.

Ledger schema: `security-kernel-rate-limit-ledger.v1`.
Category count: `14`.

## Categories

| Category | Canonical category | Owner | Limit | Window (ms) | Requests per minute | Abuse model | Review cadence |
| --- | --- | --- | --- | --- | --- | --- | --- |
| `anonymous_write` | `anonymous_write` | security-kernel | `20` | `60000` | `20` | unauthenticated write spam, sign-up funnel abuse, and anonymous mutation amplification | quarterly |
| `asset_delivery` | `asset_delivery` | runtime-platform | `3600` | `60000` | `3600` | asset scraping, hotlinking bursts, and bandwidth exhaustion against game delivery surfaces | quarterly |
| `auth_challenge` | `auth_challenge` | platform-auth | `20` | `60000` | `20` | credential stuffing, OTP guessing, MFA enrollment abuse, OAuth churn, and desktop-code probing | monthly |
| `authenticated_mutation` | `authenticated_mutation` | security-kernel | `600` | `60000` | `600` | authenticated write amplification, accidental retry storms, and tenant-local resource mutation floods | quarterly |
| `authenticated_read` | `authenticated_read` | security-kernel | `1800` | `60000` | `1800` | authenticated scraping, inventory enumeration, and runaway polling | quarterly |
| `guest_admission` | `guest_admission` | platform-auth | `12` | `60000` | `12` | guest account farming, play-session admission floods, and human-challenge bypass attempts | monthly |
| `immutable_static_asset` | `immutable_static_asset` | web-platform | `12000` | `60000` | `12000` | origin bandwidth and file-read exhaustion from one address replaying content-hashed bundle chunks past the edge cache | quarterly |
| `provider_callback` | `provider_callback` | integrations | `120` | `60000` | `120` | signed webhook replay, provider callback flooding, and bogus provider event delivery | quarterly |
| `public_read` | `public_read` | security-kernel | `3600` | `60000` | `3600` | anonymous scraping, cache-bypass polling, and public catalog enumeration | quarterly |
| `read` | `authenticated_read` | security-kernel | `1800` | `60000` | `1800` | legacy read-policy alias drift causing reads to bypass the authenticated_read budget | quarterly |
| `security_admin_read` | `security_admin_read` | security-kernel | `300` | `60000` | `300` | admin inventory scraping, incident-console polling storms, and credential metadata enumeration | monthly |
| `security_admin_write` | `security_admin_write` | security-kernel | `60` | `60000` | `60` | superadmin neutralization abuse, compromised admin session write bursts, and destructive-operation retry storms | monthly |
| `security_mutation` | `security_mutation` | security-kernel | `120` | `60000` | `120` | tenant credential churn, API-key creation floods, capability-token abuse, and security setting mutation storms | monthly |
| `static_health_local` | `static_health_local` | platform-runtime | `3600` | `60000` | `3600` | health/static route polling floods and local development endpoint abuse | quarterly |

## Category detail

### anonymous_write

- Canonical category: `anonymous_write`
- Owner: security-kernel
- Limit: `20` requests per `60000` ms window (`20` per minute)
- Keying: route method/path + request identity IP hash + resolved tenant/resource key
- Abuse model: unauthenticated write spam, sign-up funnel abuse, and anonymous mutation amplification
- Alert threshold: page when sustained deny rate exceeds 10 percent for 5 minutes or when a single route exceeds 500 denies in 10 minutes
- Review cadence: quarterly

### asset_delivery

- Canonical category: `asset_delivery`
- Owner: runtime-platform
- Limit: `3600` requests per `60000` ms window (`3600` per minute)
- Keying: route method/path + player/browser/credential/IP identity + deployment/game asset resource key
- Abuse model: asset scraping, hotlinking bursts, and bandwidth exhaustion against game delivery surfaces
- Alert threshold: page when asset delivery denies exceed 2 percent for 10 minutes on a game or deployment
- Review cadence: quarterly

### auth_challenge

- Canonical category: `auth_challenge`
- Owner: platform-auth
- Limit: `20` requests per `60000` ms window (`20` per minute)
- Keying: route method/path + account/credential/IP identity + auth resource key
- Abuse model: credential stuffing, OTP guessing, MFA enrollment abuse, OAuth churn, and desktop-code probing
- Alert threshold: page on burst denies for a principal or IP hash, or when challenge failures exceed baseline by 3x for 5 minutes
- Review cadence: monthly

### authenticated_mutation

- Canonical category: `authenticated_mutation`
- Owner: security-kernel
- Limit: `600` requests per `60000` ms window (`600` per minute)
- Keying: route method/path + principal/credential identity + resolved tenant/resource key
- Abuse model: authenticated write amplification, accidental retry storms, and tenant-local resource mutation floods
- Alert threshold: page when deny rate exceeds 5 percent for 10 minutes on a route or tenant
- Review cadence: quarterly

### authenticated_read

- Canonical category: `authenticated_read`
- Owner: security-kernel
- Limit: `1800` requests per `60000` ms window (`1800` per minute)
- Keying: route method/path + principal/credential identity + resolved tenant/resource key
- Abuse model: authenticated scraping, inventory enumeration, and runaway polling
- Alert threshold: ticket when route denies exceed 5 percent for 15 minutes; page for platform-admin read routes
- Review cadence: quarterly

### guest_admission

- Canonical category: `guest_admission`
- Owner: platform-auth
- Limit: `12` requests per `60000` ms window (`12` per minute)
- Keying: route method/path + request identity IP hash + guest admission resource key
- Abuse model: guest account farming, play-session admission floods, and human-challenge bypass attempts
- Alert threshold: page when guest admission denies exceed 20 percent for 5 minutes or challenge failures spike by 3x
- Review cadence: monthly

### immutable_static_asset

- Canonical category: `immutable_static_asset`
- Owner: web-platform
- Limit: `12000` requests per `60000` ms window (`12000` per minute)
- Keying: route method/path + request identity IP hash (a browser's chunk load carries no credential, so the client address is the bucket)
- Abuse model: origin bandwidth and file-read exhaustion from one address replaying content-hashed bundle chunks past the edge cache
- Alert threshold: page when denies exceed 1 percent of chunk requests for 10 minutes, which means legitimate cold boots are being refused
- Review cadence: quarterly

### provider_callback

- Canonical category: `provider_callback`
- Owner: integrations
- Limit: `120` requests per `60000` ms window (`120` per minute)
- Keying: route method/path + provider callback identity/IP + resolved provider delivery resource key
- Abuse model: signed webhook replay, provider callback flooding, and bogus provider event delivery
- Alert threshold: page on signature failure bursts or when callback denies exceed 10 percent for 5 minutes
- Review cadence: quarterly

### public_read

- Canonical category: `public_read`
- Owner: security-kernel
- Limit: `3600` requests per `60000` ms window (`3600` per minute)
- Keying: route method/path + request identity IP hash + public resource key
- Abuse model: anonymous scraping, cache-bypass polling, and public catalog enumeration
- Alert threshold: ticket when route denies exceed 5 percent for 15 minutes; page for sustained CDN bypass
- Review cadence: quarterly

### read

- Canonical category: `authenticated_read`
- Owner: security-kernel
- Limit: `1800` requests per `60000` ms window (`1800` per minute)
- Keying: legacy alias for authenticated_read: route method/path + principal/credential identity + resolved tenant/resource key
- Abuse model: legacy read-policy alias drift causing reads to bypass the authenticated_read budget
- Alert threshold: ticket on any new route using read until it is migrated or explicitly justified
- Review cadence: quarterly

### security_admin_read

- Canonical category: `security_admin_read`
- Owner: security-kernel
- Limit: `300` requests per `60000` ms window (`300` per minute)
- Keying: route method/path + platform admin principal identity + resolved security resource key
- Abuse model: admin inventory scraping, incident-console polling storms, and credential metadata enumeration
- Alert threshold: page when denies occur for PlatformOwner/PlatformSupport or exceed 2 percent for 5 minutes
- Review cadence: monthly

### security_admin_write

- Canonical category: `security_admin_write`
- Owner: security-kernel
- Limit: `60` requests per `60000` ms window (`60` per minute)
- Keying: route method/path + platform admin principal identity + resolved target security resource key
- Abuse model: superadmin neutralization abuse, compromised admin session write bursts, and destructive-operation retry storms
- Alert threshold: page on any deny burst, any unexpected source geography, or more than 5 destructive commands per minute
- Review cadence: monthly

### security_mutation

- Canonical category: `security_mutation`
- Owner: security-kernel
- Limit: `120` requests per `60000` ms window (`120` per minute)
- Keying: route method/path + organization/workspace principal or machine credential + resolved credential/security resource key
- Abuse model: tenant credential churn, API-key creation floods, capability-token abuse, and security setting mutation storms
- Alert threshold: page when denies exceed 5 percent for 5 minutes or credential mutations spike by 3x
- Review cadence: monthly

### static_health_local

- Canonical category: `static_health_local`
- Owner: platform-runtime
- Limit: `3600` requests per `60000` ms window (`3600` per minute)
- Keying: route method/path + request identity IP hash + static/local resource key
- Abuse model: health/static route polling floods and local development endpoint abuse
- Alert threshold: ticket when static/local denies exceed 10 percent for 15 minutes outside synthetic checks
- Review cadence: quarterly
