Registry / web-framework / flask-limiter

flask-limiter

JSON →
library4.1.1pypypi✓ verified 35d ago

Flask-Limiter is an active Python extension that adds rate limiting capabilities to Flask applications, preventing abuse and ensuring stability. It allows configuration of limits at various levels (application-wide, per Blueprint, per route) and supports multiple storage backends like Redis, Memcached, MongoDB, and Valkey. The current version is 4.1.1, with a regular release cadence.

web-frameworkauth-security
Install & Compatibility
Where this runs
tested against v4.1.1 · pip install
no network on importno background threads
Install × environment matrix
Each cell = how many times install + import succeeded across repeated harness runs. Partial = flaky.
glibc = Debian/Ubuntu slim · musl = Alpine Linux
musl
py 3.103.9150 runs
installs and imports cleanly · install 0.0s · import 0.779s · 37.5MB
glibc
py 3.103.9150 runs
installs and imports cleanly · install 3.6s · import 0.699s · 38MB
38MB installed
● package 38MB
Code
Verified usage

Verified import paths — ran on the pinned version, not inferred.

from flask_limiter import Limiter
from flask_limiter.util import get_remote_address

As of v4.0.0, internal submodules are prefixed with an underscore, and direct imports from them (e.g., `flask_limiter.limits`) are deprecated. Import from the root `flask_limiter` namespace instead.

from flask_limiter import Limit

Initializes a Flask application with global and per-route rate limits. It uses `get_remote_address` as the default key function and specifies a default storage URI. Routes demonstrate application-wide limits, specific route limits, combined limits, and exemptions. An error handler for HTTP 429 is included for custom responses.

import os from flask import Flask from flask_limiter import Limiter from flask_limiter.util import get_remote_address app = Flask(__name__) # Configure storage_uri, using in-memory for example, or from an environment variable # In-memory storage is for development/testing only and should not be used in production with multiple workers. # For production, use backends like Redis: 'redis://localhost:6379' storage_uri = os.environ.get('FLASK_RATELIMIT_STORAGE_URI', 'memory://') limiter = Limiter( key_func=get_remote_address, app=app, default_limits=["200 per day", "50 per hour"], storage_uri=storage_uri, strategy="fixed-window" # Or 'moving-window', 'sliding-window-counter' ) @app.route("/slow") @limiter.limit("1 per day") def slow(): return ":(" @app.route("/medium") @limiter.limit("1/second", override_defaults=False) def medium(): return ":|" @app.route("/fast") def fast(): return ":)" @app.route("/ping") @limiter.exempt def ping(): return "PONG" # Example error handler for rate limit exceeded (HTTP 429) @app.errorhandler(429) def ratelimit_handler(e): return f"Rate limit exceeded: {e.description}", 429 if __name__ == '__main__': app.run(debug=True)
Debug
Known footguns
breakingVersion 4.0.0 introduced significant breaking changes in module structure and limit definition. All internal submodules are now prefixed with an underscore, and direct imports from them (e.g., `from flask_limiter.limits import Limit`) are deprecated. Instead, import classes like `Limit`, `RouteLimit`, `ApplicationLimit`, and `MetaLimit` directly from the root `flask_limiter` namespace.
breakingVersion 3.0.0 changed the `Limiter` constructor arguments. `key_func` is now a mandatory positional argument, and all other arguments must be passed as keyword arguments. The `RATELIMIT_STORAGE_URL` configuration variable was removed, and legacy Flask < 2 compatibility was dropped.
gotchaUsing in-memory storage (`memory://`) in production with multiple worker processes will lead to inaccurate and unreliable rate limiting. Each worker will maintain its own independent limit state, making global rate limits ineffective.
deprecatedThe 3.13 release was yanked from PyPI due to compatibility issues with Flask-AppBuilder and Airflow. Users who installed this specific version might encounter unexpected behavior or errors.
breakingFlask-Limiter frequently adjusts its supported Python versions. For example, Python 3.9 support was dropped in v3.12, and Python 3.8 support was dropped in v3.9.0. Currently, Python >=3.10 is required.
gotchaWhen deploying behind a proxy (e.g., Nginx, Gunicorn), `get_remote_address` might return the proxy's IP address instead of the client's. This can lead to all requests being limited by the proxy's IP, effectively acting as a single global limit for all users.
Upgrade
Version history

Breaking-change detection hasn't run for this library yet.

Audit
Security & dependencies

CVE tracking and dependency tree are planned for a later release.

Agent activity
22 hits · last 30 days
claudebot
5
gptbot
4
ahrefsbot
3
dotbot
1
amazonbot
1
chatgpt-user
1
Resources