security/rate-limiting.md
Rate Limiting
Rate limiting applies to /api/* routes except GET /api/v1/health and OPTIONS.
Default Limits
- per-IP window max:
240 - per-API-key window max:
480 - per-IP concurrent max:
48 - window:
60000ms
Headers
X-RateLimit-LimitX-RateLimit-RemainingX-RateLimit-ResetRetry-After(on 429)
Env Overrides
MINO_RATE_LIMIT_ENABLEDMINO_RATE_LIMIT_WINDOW_MSMINO_RATE_LIMIT_IP_MAXMINO_RATE_LIMIT_KEY_MAXMINO_RATE_LIMIT_CONCURRENT_IP