Skip to content
CortexDocs
Gateway · Set rate limits

Set Gateway rate limits

Create or edit an organization requests-per-minute limit on an enabled, supported Gateway path.

Review current limits

Current controls

Rate limits control throughput separately from money. The current console supports organization-wide requests-per-minute limits. The creation form does not expose token throughput, parallelism ceilings or additional scopes.

Before you begin

You need the organization's Admin role, a live management view and an enabled Gateway control path. Create rate limit is unavailable while Gateway status is loading, unavailable or disabled. Sample records do not permit writes.

Create a requests-per-minute limit

  1. Open Gateway → Rate Limits for the intended organization.
  2. Select Create rate limit.
  3. Enter a positive whole number in Limit per minute. The created limit has organization scope; the form does not create person, Team, model or provider filters.
  4. Select Create rate limit to save.
  5. Confirm the new organization row, RPM value and active status in the refreshed list.

Change an existing limit

  1. Open the edit action for a supported organization RPM record.
  2. Change Limit per minute and, when required, choose Active or Disabled under Status.
  3. Select Save changes.
  4. Confirm the refreshed row. Unsupported scopes or record shapes remain read-only; do not infer that every listed record is editable.

Changes reach enrolled Cortex Defender devices after their configuration poll. A saved active row does not prove every client received the limit.

Verify the affected path

Use the deployment's controlled request-path test to confirm delivery and an applicable HTTP 429 refusal. Keep recent denial records separate from the current counting window. Denial telemetry is best effort; an empty history does not establish that the limit was ignored or that every request was admitted.

Counting-backend failure can admit traffic. See Policy and enforcement boundaries and current request errors. Do not assume that a particular reset header or retry time is returned unless the deployed response supplies it.

Continue

Was this helpful?