Security & Compliance
Rate Limits
Per-endpoint rate limits and per-tenant network policy. Per-client and per-tenant tiers are still pending — see GAP-ANALYSIS P2.
Per-endpoint rate limits and per-tenant network policy. Per-client and per-tenant tiers are still pending — see GAP-ANALYSIS P2.
backend/internal/platform/ratelimit/limiter.go.POST /v1/auth/loginPOST /v1/auth/refreshPOST /v1/auth/signupPOST /v1/auth/forgot-passwordPOST /v1/oauth/token (client_credentials)Other authed endpointsAllowlist (0)
No allowlist — open to all source IPs.
Denylist (0)
No denied CIDRs.
Per-tenant rate limits coming soon.
Today every tenant shares the same global gateway limits. Tenant-tier limits (per plan) are tracked as P2 in documents/GAP-ANALYSIS.md.