Configure · Rate Limits
Rate Limit & Abuse Protection
The public chat widget calls a paid LLM per message with no login required. This page shows the per-visitor-IP limits currently in effect, lets you trigger a safe test block on your own account, and lists any real visitors that have actually been blocked.
Live limits (per visitor IP)
Configured via
RATE_LIMIT_CHAT_PER_MINUTE / RATE_LIMIT_CHAT_PER_DAY— applies to both /api/chat/message and /api/chat/stream (they share one budget per IP).12 requests / 1m (minute)
300 requests / 1d (day)
Test the limiter
Sends a lightweight test request — no LLM call, no real visitor affected — against a separate 3-per-15-second demo limit tied to your own admin account. Click it four times quickly to see a block happen.
Recent real blocks
0 block(s) from 0 IP(s) in the last 24h.
No visitor has been rate-limited in the last 24 hours.