Your search API key is visible in your site's front end, so anyone can use it, and every request they send counts towards your usage. A rate limit caps how many search requests can be made with the key per hour, per IP address (or per userToken). It's one of the simplest ways to limit the effect of automated traffic on your usage.
Set a rate limit
In the dashboard:
- Go to the API Keys section of your dashboard settings.
- Open All API Keys.
- Create a new API key, or select an existing one to update.
- Enter a value for Max API calls/IP/hour.
- Click Create or Update.
With the API, set maxQueriesPerIPPerHour when creating or updating a key with addApiKey or updateApiKey.
A key used in your front end should only have the search right. See the access control list for the available rights and restrictions. If you create a new key, update your site to use it.
Choose a value
- Divide by three on a standard cluster. Each cluster has three servers, and each server applies the limit separately. With a limit of 100, each IP address can make up to 300 search requests an hour. Divide the limit you have in mind by three before entering it. This doesn't apply on Dynamically Scaling Infrastructure (your cluster name starts with M). If you're not sure which you have, see How can I monitor my Algolia servers, clusters, and DSNs?
- Start high, then lower it gradually. Begin above what you think you need, so you don't limit real users, and lower it while watching the effect on your usage. Your Search API Logs, or the getLogs method, list recent individual requests with the IP address that sent each one. They're a small sample (the last seven days, with up to 1,000 requests logged per server) and don't total requests per IP, so treat them as a rough guide rather than a precise measure. If you need a fuller picture, contact the Support team.
- Allow for shared IP addresses. Many real users can share one address, for example in an office or on a mobile network.
If an IP address goes over the limit within the past hour, Algolia returns a 429 Too Many Requests error.
What a rate limit can and can't do
- It works well against traffic from a small number of addresses.
- It can't stop bots spread across many IP addresses. Each address sends only a few requests, so any limit tight enough to catch them also limits real users.
- It doesn't suit backend search as it stands. All requests come from your server's IP address. See How do I deal with bots if I use backend search?
Rate limits apply per combination of IP address or userToken, API key and application ID. Secured API keys inherit the rate limit of the base key they're generated from.
A rate limit is one layer of protection. For others, see How can I mitigate bots impacting my usage of Algolia?