Set Gateway rate limits
Create or edit an organization requests-per-minute limit on an enabled, supported Gateway path.
Current controls
Rate limits control throughput separately from money. The current console supports organization-wide requests-per-minute limits. The creation form does not expose token throughput, parallelism ceilings or additional scopes.
Before you begin
You need the organization's Admin role, a live management view and an enabled Gateway control path. Create rate limit is unavailable while Gateway status is loading, unavailable or disabled. Sample records do not permit writes.
Create a requests-per-minute limit
- Open Gateway → Rate Limits for the intended organization.
- Select Create rate limit.
- Enter a positive whole number in Limit per minute. The created limit has organization scope; the form does not create person, Team, model or provider filters.
- Select Create rate limit to save.
- Confirm the new organization row, RPM value and active status in the refreshed list.
Change an existing limit
- Open the edit action for a supported organization RPM record.
- Change Limit per minute and, when required, choose Active or Disabled under Status.
- Select Save changes.
- Confirm the refreshed row. Unsupported scopes or record shapes remain read-only; do not infer that every listed record is editable.
Changes reach enrolled Cortex Defender devices after their configuration poll. A saved active row does not prove every client received the limit.
Verify the affected path
Use the deployment's controlled request-path test to confirm delivery and an applicable HTTP 429 refusal. Keep recent denial records separate from the current counting window. Denial telemetry is best effort; an empty history does not establish that the limit was ignored or that every request was admitted.
Counting-backend failure can admit traffic. See Policy and enforcement boundaries and current request errors. Do not assume that a particular reset header or retry time is returned unless the deployed response supplies it.
Continue
- Manage budgets for monetary limits.
- Restrict model and provider access for scoped deny rules.