Generated Reference
Rate Limit Reference
Sources:
docs/security-kernel-rate-limit-ledger.json.engine v1.0.234Copy for LLM
This generated snapshot is derived from the security-kernel rate-limit ledger (docs/security-kernel-rate-limit-ledger.json, projected from server/src/modules/security-kernel/rateLimiter.ts). Each row is one rate-limit category applied to HTTP routes by the security kernel; the route reference names the category each operation carries in its Rate limit column.
Ledger schema: security-kernel-rate-limit-ledger.v1. Category count: 14.
Categories
| Category | Canonical category | Owner | Limit | Window (ms) | Requests per minute | Abuse model | Review cadence |
|---|---|---|---|---|---|---|---|
anonymous_write | anonymous_write | security-kernel | 20 | 60000 | 20 | unauthenticated write spam, sign-up funnel abuse, and anonymous mutation amplification | quarterly |
asset_delivery | asset_delivery | runtime-platform | 3600 | 60000 | 3600 | asset scraping, hotlinking bursts, and bandwidth exhaustion against game delivery surfaces | quarterly |
auth_challenge | auth_challenge | platform-auth | 20 | 60000 | 20 | credential stuffing, OTP guessing, MFA enrollment abuse, OAuth churn, and desktop-code probing | monthly |
authenticated_mutation | authenticated_mutation | security-kernel | 600 | 60000 | 600 | authenticated write amplification, accidental retry storms, and tenant-local resource mutation floods | quarterly |
authenticated_read | authenticated_read | security-kernel | 1800 | 60000 | 1800 | authenticated scraping, inventory enumeration, and runaway polling | quarterly |
guest_admission | guest_admission | platform-auth | 12 | 60000 | 12 | guest account farming, play-session admission floods, and human-challenge bypass attempts | monthly |
immutable_static_asset | immutable_static_asset | web-platform | 12000 | 60000 | 12000 | origin bandwidth and file-read exhaustion from one address replaying content-hashed bundle chunks past the edge cache | quarterly |
provider_callback | provider_callback | integrations | 120 | 60000 | 120 | signed webhook replay, provider callback flooding, and bogus provider event delivery | quarterly |
public_read | public_read | security-kernel | 3600 | 60000 | 3600 | anonymous scraping, cache-bypass polling, and public catalog enumeration | quarterly |
read | authenticated_read | security-kernel | 1800 | 60000 | 1800 | legacy read-policy alias drift causing reads to bypass the authenticated_read budget | quarterly |
security_admin_read | security_admin_read | security-kernel | 300 | 60000 | 300 | admin inventory scraping, incident-console polling storms, and credential metadata enumeration | monthly |
security_admin_write | security_admin_write | security-kernel | 60 | 60000 | 60 | superadmin neutralization abuse, compromised admin session write bursts, and destructive-operation retry storms | monthly |
security_mutation | security_mutation | security-kernel | 120 | 60000 | 120 | tenant credential churn, API-key creation floods, capability-token abuse, and security setting mutation storms | monthly |
static_health_local | static_health_local | platform-runtime | 3600 | 60000 | 3600 | health/static route polling floods and local development endpoint abuse | quarterly |
Category detail
anonymous_write
- Canonical category:
anonymous_write - Owner: security-kernel
- Limit:
20requests per60000ms window (20per minute) - Keying: route method/path + request identity IP hash + resolved tenant/resource key
- Abuse model: unauthenticated write spam, sign-up funnel abuse, and anonymous mutation amplification
- Alert threshold: page when sustained deny rate exceeds 10 percent for 5 minutes or when a single route exceeds 500 denies in 10 minutes
- Review cadence: quarterly
asset_delivery
- Canonical category:
asset_delivery - Owner: runtime-platform
- Limit:
3600requests per60000ms window (3600per minute) - Keying: route method/path + player/browser/credential/IP identity + deployment/game asset resource key
- Abuse model: asset scraping, hotlinking bursts, and bandwidth exhaustion against game delivery surfaces
- Alert threshold: page when asset delivery denies exceed 2 percent for 10 minutes on a game or deployment
- Review cadence: quarterly
auth_challenge
- Canonical category:
auth_challenge - Owner: platform-auth
- Limit:
20requests per60000ms window (20per minute) - Keying: route method/path + account/credential/IP identity + auth resource key
- Abuse model: credential stuffing, OTP guessing, MFA enrollment abuse, OAuth churn, and desktop-code probing
- Alert threshold: page on burst denies for a principal or IP hash, or when challenge failures exceed baseline by 3x for 5 minutes
- Review cadence: monthly
authenticated_mutation
- Canonical category:
authenticated_mutation - Owner: security-kernel
- Limit:
600requests per60000ms window (600per minute) - Keying: route method/path + principal/credential identity + resolved tenant/resource key
- Abuse model: authenticated write amplification, accidental retry storms, and tenant-local resource mutation floods
- Alert threshold: page when deny rate exceeds 5 percent for 10 minutes on a route or tenant
- Review cadence: quarterly
authenticated_read
- Canonical category:
authenticated_read - Owner: security-kernel
- Limit:
1800requests per60000ms window (1800per minute) - Keying: route method/path + principal/credential identity + resolved tenant/resource key
- Abuse model: authenticated scraping, inventory enumeration, and runaway polling
- Alert threshold: ticket when route denies exceed 5 percent for 15 minutes; page for platform-admin read routes
- Review cadence: quarterly
guest_admission
- Canonical category:
guest_admission - Owner: platform-auth
- Limit:
12requests per60000ms window (12per minute) - Keying: route method/path + request identity IP hash + guest admission resource key
- Abuse model: guest account farming, play-session admission floods, and human-challenge bypass attempts
- Alert threshold: page when guest admission denies exceed 20 percent for 5 minutes or challenge failures spike by 3x
- Review cadence: monthly
immutable_static_asset
- Canonical category:
immutable_static_asset - Owner: web-platform
- Limit:
12000requests per60000ms window (12000per minute) - Keying: route method/path + request identity IP hash (a browser's chunk load carries no credential, so the client address is the bucket)
- Abuse model: origin bandwidth and file-read exhaustion from one address replaying content-hashed bundle chunks past the edge cache
- Alert threshold: page when denies exceed 1 percent of chunk requests for 10 minutes, which means legitimate cold boots are being refused
- Review cadence: quarterly
provider_callback
- Canonical category:
provider_callback - Owner: integrations
- Limit:
120requests per60000ms window (120per minute) - Keying: route method/path + provider callback identity/IP + resolved provider delivery resource key
- Abuse model: signed webhook replay, provider callback flooding, and bogus provider event delivery
- Alert threshold: page on signature failure bursts or when callback denies exceed 10 percent for 5 minutes
- Review cadence: quarterly
public_read
- Canonical category:
public_read - Owner: security-kernel
- Limit:
3600requests per60000ms window (3600per minute) - Keying: route method/path + request identity IP hash + public resource key
- Abuse model: anonymous scraping, cache-bypass polling, and public catalog enumeration
- Alert threshold: ticket when route denies exceed 5 percent for 15 minutes; page for sustained CDN bypass
- Review cadence: quarterly
read
- Canonical category:
authenticated_read - Owner: security-kernel
- Limit:
1800requests per60000ms window (1800per minute) - Keying: legacy alias for authenticated_read: route method/path + principal/credential identity + resolved tenant/resource key
- Abuse model: legacy read-policy alias drift causing reads to bypass the authenticated_read budget
- Alert threshold: ticket on any new route using read until it is migrated or explicitly justified
- Review cadence: quarterly
security_admin_read
- Canonical category:
security_admin_read - Owner: security-kernel
- Limit:
300requests per60000ms window (300per minute) - Keying: route method/path + platform admin principal identity + resolved security resource key
- Abuse model: admin inventory scraping, incident-console polling storms, and credential metadata enumeration
- Alert threshold: page when denies occur for PlatformOwner/PlatformSupport or exceed 2 percent for 5 minutes
- Review cadence: monthly
security_admin_write
- Canonical category:
security_admin_write - Owner: security-kernel
- Limit:
60requests per60000ms window (60per minute) - Keying: route method/path + platform admin principal identity + resolved target security resource key
- Abuse model: superadmin neutralization abuse, compromised admin session write bursts, and destructive-operation retry storms
- Alert threshold: page on any deny burst, any unexpected source geography, or more than 5 destructive commands per minute
- Review cadence: monthly
security_mutation
- Canonical category:
security_mutation - Owner: security-kernel
- Limit:
120requests per60000ms window (120per minute) - Keying: route method/path + organization/workspace principal or machine credential + resolved credential/security resource key
- Abuse model: tenant credential churn, API-key creation floods, capability-token abuse, and security setting mutation storms
- Alert threshold: page when denies exceed 5 percent for 5 minutes or credential mutations spike by 3x
- Review cadence: monthly
static_health_local
- Canonical category:
static_health_local - Owner: platform-runtime
- Limit:
3600requests per60000ms window (3600per minute) - Keying: route method/path + request identity IP hash + static/local resource key
- Abuse model: health/static route polling floods and local development endpoint abuse
- Alert threshold: ticket when static/local denies exceed 10 percent for 15 minutes outside synthetic checks
- Review cadence: quarterly