Someone is spamming your AI feature? Rate limit it on Vercel
Ship ItChecked against the official source
Source checked 3 Oct 2026 · Published 4 Oct 2026 · Last reviewed 4 Oct 2026 · By Ctrl+Z Therapy (how we test)
The short answer
If your app is on Vercel, its firewall can rate limit a route on every plan: it controls how many times a request from the same source can hit your app. A new rule starts at 100 requests per 60 seconds, and past that the default response is 429, Too Many Requests. The Hobby plan gets one rate limit rule per project, so put it on your AI route.
What to do
- In your Vercel project, open Firewall, then Configure, then New Rule.
- Match your AI route and choose Rate Limit.
- Review the rule and publish it.
- Not on Vercel? Paste this into your AI tool: "Add a per-user rate limit to our AI endpoint, for example 20 requests per minute, and return a clear error when it's hit."
Source
Checked on 3 Oct 2026. Prices, limits and settings change, so check the source before you rely on them.