Skip to main content

List ratelimit overrides

Retrieve a paginated list of all rate limit overrides in a namespace.

Use this to audit rate limiting policies, build admin dashboards, or manage override configurations.

Important: Results are paginated. Use the cursor parameter to retrieve additional pages when more results are available.

Permissions: Requires ratelimit.*.read_override or ratelimit.<namespace_id>.read_override

1 min read
post/v2/ratelimit.listOverrides
Request example
Response
post/v2/ratelimit.listOverrides

Authorization

Authorizationstringheaderrequired#

Unkey uses bearer tokens for authentication. Public integrations use root keys, while the dashboard proxy uses short-lived JWTs.
To authenticate, include the token in the Authorization header of each request:

Root keys have specific permissions attached to them, controlling what operations they can perform. Legacy permissions use tuple strings like api.*.create_key; resource permissions use Unkey Resource Names plus actions, like unkey:v1:ws_123:keyspaces/*#create_key.
Security best practices:

  • Keep root keys secure and never expose them in client-side code
  • Use different root keys for different environments
  • Rotate keys periodically, especially after team member departures
  • Create keys with minimal necessary permissions following least privilege principle
  • Monitor key usage with audit logs.

Body

application/json
namespacestringrequired#
The id or name of the rate limit namespace to list overrides for.

Length: 1–512

cursorstring#
Pagination cursor from a previous response. Include this when fetching subsequent pages of results. Each response containing more results than the requested limit will include a cursor value in the pagination object that can be used here.
limitinteger#

Maximum number of override entries to return in a single response. Use this to control response size and loading performance.

  • Lower values (10-20): Better for UI displays and faster response times
  • Higher values (50-100): Better for data exports or bulk operations
  • Default (10): Suitable for most dashboard views

Results exceeding this limit will be paginated, with a cursor provided for fetching subsequent pages.

Default: 10

Range: 1–100

Responses

application/json
Overrides retrieved successfully. Includes pagination metadata if more results are available.
metaobjectrequired#
Metadata object included in every API response. This provides context about the request and is essential for debugging, audit trails, and support inquiries. The requestId is particularly important when troubleshooting issues with the Unkey support team.
Show child attributes
requestIdstringrequired#
A unique id for this request. Always include this ID when contacting support about a specific API request. This identifier allows Unkey's support team to trace the exact request through logs and diagnostic systems to provide faster assistance.
dataobject[]required#
Show child attributes
overrideIdstringrequired#
The unique identifier of this specific rate limit override. This ID is generated when the override is created and can be used for management operations like updating or deleting the override.

Length: 1–255

durationintegerrequired#
The duration in milliseconds for this override's rate limit window. This may differ from the default duration for the namespace, allowing custom time windows for specific entities. After this duration elapses, the rate limit counter for affected identifiers resets to zero.

Range: >= 1000

identifierstringrequired#

The identifier pattern this override applies to. This determines which entities receive the custom rate limit.

This can be:

  • An exact identifier for a specific entity
  • A pattern with wildcards for matching multiple entities

Wildcard examples:

  • 'admin_*' matches any identifier starting with 'admin_'
  • '*_test' matches any identifier ending with '_test'
  • 'premium' matches any identifier containing 'premium'

More complex patterns can combine multiple wildcards. Detailed documentation on pattern matching rules is available at https://www.unkey.com/docs/ratelimiting/overrides#wildcard-rules

Length: 1–255

limitintegerrequired#

The maximum number of requests allowed for entities matching this override. This replaces the default limit for the namespace when applied.

Common use cases:

  • Higher limits for premium customers
  • Reduced limits for abusive or suspicious entities
  • Zero limit to completely block specific patterns
  • Custom tier-based limits for different customer segments

Range: >= 0

paginationobjectrequired#
Pagination metadata for list endpoints. Provides information necessary to traverse through large result sets efficiently using cursor-based pagination.
Show child attributes
cursorstring#

Opaque pagination token for retrieving the next page of results.
Include this exact value in the cursor field of subsequent requests.
Cursors are temporary and may expire after extended periods.

Length: 1–1024

hasMorebooleanrequired#

Indicates whether additional results exist beyond this page.
When true, use the cursor to fetch the next page.
When false, you have reached the end of the result set.