<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with rate limiting]]></title><description><![CDATA[A list of topics that have been tagged with rate limiting]]></description><link>https://fusionauth.io/community/forum/tags/rate limiting</link><generator>RSS for Node</generator><lastBuildDate>Sun, 17 May 2026 03:23:12 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/rate limiting.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[How to Handle CAPTCHA and Rate Limits for Automated Testing in FusionAuth]]></title><description><![CDATA[<p dir="auto">You’ll need to disable or mock CAPTCHA in a test environment and adjust rate-limit settings in FusionAuth’s config or use test API keys to avoid hitting production limits during automated runs.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3035/how-to-handle-captcha-and-rate-limits-for-automated-testing-in-fusionauth</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3035/how-to-handle-captcha-and-rate-limits-for-automated-testing-in-fusionauth</guid><dc:creator><![CDATA[james61972]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Managing Rate Limits and CAPTCHA During FusionAuth Cloud Integration]]></title><description><![CDATA[<p dir="auto">These challenges are expected because of the <strong>security protections</strong> in place on FusionAuth Cloud deployments. One option is indeed to <strong>self-host FusionAuth</strong>, which gives you full control over rate limits and CAPTCHA settings.</p>
<p dir="auto">Alternatively, you could <strong>add your IP address to FusionAuth’s allowlist</strong>, which can exempt you from certain rate limits and CAPTCHA checks. Details on this approach and the requirements are documented here:<br />
<a href="https://fusionauth.io/docs/get-started/run-in-the-cloud/cloud#captcha-and-rate-limits" rel="nofollow ugc">CAPTCHA and Rate Limits - FusionAuth Cloud</a></p>
]]></description><link>https://fusionauth.io/community/forum/topic/2990/managing-rate-limits-and-captcha-during-fusionauth-cloud-integration</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/2990/managing-rate-limits-and-captcha-during-fusionauth-cloud-integration</guid><dc:creator><![CDATA[wesley]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Rate limiting FusionAuth API access]]></title><description><![CDATA[<p dir="auto">You have a couple of options.</p>
<p dir="auto">If you are self hosting, use a WAF, CDN or firewall to rate limit access to FusionAuth.</p>
<p dir="auto">If you are using FusionAuth Cloud, we have protection in place to ensure customers don’t get DDoSed; additionally, all customer servers are monitored for responsiveness and availability.</p>
<p dir="auto">If you need more rate limiting options, we're working on it: <a href="https://github.com/FusionAuth/fusionauth-issues/issues/905" rel="nofollow ugc">https://github.com/FusionAuth/fusionauth-issues/issues/905</a></p>
]]></description><link>https://fusionauth.io/community/forum/topic/1092/rate-limiting-fusionauth-api-access</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/1092/rate-limiting-fusionauth-api-access</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Rate limit password reset requests?]]></title><description><![CDATA[<p dir="auto">This is not currently handled by FusionAuth. You would have to use another application firewall of some sort that offers rate limiting. Here's an example for nginx: <a href="https://docs.nginx.com/nginx/admin-guide/security-controls/controlling-access-proxied-http/" rel="nofollow ugc">https://docs.nginx.com/nginx/admin-guide/security-controls/controlling-access-proxied-http/</a></p>
<p dir="auto">We have discussed adding this feature, but due to the other options available it has not yet been prioritized. Feel free to open a feature request on GitHub.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/361/rate-limit-password-reset-requests</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/361/rate-limit-password-reset-requests</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Rate limiting login attempts]]></title><description><![CDATA[<p dir="auto">Please check out <a href="https://fusionauth.io/docs/v1/tech/tutorials/setting-up-user-account-lockout" rel="nofollow ugc">https://fusionauth.io/docs/v1/tech/tutorials/setting-up-user-account-lockout</a> which walks you through the steps to lock logins after a configurable number of attempts.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/192/rate-limiting-login-attempts</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/192/rate-limiting-login-attempts</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>