generated: '2026-09-04' method: searched source: https://raw.githubusercontent.com/appsmithorg/appsmith/release/app/server/appsmith-server/src/main/java/com/appsmith/server/ratelimiting/RateLimitConfig.java provider: Appsmith providerId: appsmith name: Appsmith rate limits note: Read from the first-party enforcement code, not from a marketing page. Appsmith publishes no rate-limit reference on docs.appsmith.com; the numbers below are the bucket4j bandwidth configurations compiled into the open-source server (Apache-2.0) plus the Caddy edge limiter shipped in the Docker image. Because Appsmith is self-hosted, an operator can change every one of them. limit_count: 6 headers: limit: null remaining: null reset: null retryAfter: null policy: null note: 'NO RateLimit-* or Retry-After response headers are emitted. The runtime signal is the body: HTTP 429 with {"responseMeta":{"error":{"code":"AE-TMR-4029","title":"Too many requests"}}}. An agent must key its backoff on the status code and the AE-TMR-4029 code, because there is no header telling it when to retry.' responseCodes: throttled: 429 errorCode: AE-TMR-4029 datasourceThrottled: AE-TMR-4030 limits: - name: Caddy edge limiter scope: per-client-IP metric: requests limit: 100 window: 1s burst: null configurable: APPSMITH_RATE_LIMIT (set to "disabled" to turn off) default: true source: deploy/docker/fs/opt/appsmith/caddy-reconfigure.mjs note: Keyed on Caddy's trusted-resolved {client_ip}, deliberately not on X-Forwarded-For (GHSA-qrgm-h8c4-jjf7). - name: MCP authentication scope: per-user metric: authentication attempts limit: 5 window: 1m bucket_key: mcp_authentication source: RateLimitConfig.java - name: Login scope: per-email metric: failed login attempts limit: 5 window: 1d bucket_key: login source: RateLimitConfig.java note: 'On exhaustion the account is suspended for 24 hours: "Your account is suspended for 24 hours. Please reset your password to continue".' - name: Test datasource / execute query scope: per-user metric: requests limit: 3 window: 5s bucket_key: test_datasource_or_execute_query source: RateLimitConfig.java - name: Resend email verification scope: per-email metric: requests limit: 5 window: 1d bucket_key: resend_email_verification source: RateLimitConfig.java - name: Ask AI assistant scope: per-user metric: requests limit: 20 window: 1m bucket_key: ai_assistant_request source: RateLimitConfig.java note: 'Explicitly a denial-of-wallet control: every request spends the organization''s own third-party LLM credits.' storage: Distributed bucket4j buckets backed by Redis (LettuceBasedProxyManager), so limits hold across replicas. evidence: - url: https://github.com/appsmithorg/appsmith/blob/release/app/server/appsmith-server/src/main/java/com/appsmith/server/ratelimiting/RateLimitConfig.java what: the five bucket4j bandwidth configurations - url: https://github.com/appsmithorg/appsmith/blob/release/deploy/docker/fs/opt/appsmith/caddy-reconfigure.mjs what: APPSMITH_RATE_LIMIT default 100 events / 1s window - url: https://github.com/appsmithorg/appsmith/blob/release/app/server/appsmith-server/src/main/java/com/appsmith/server/exceptions/AppsmithError.java what: TOO_MANY_REQUESTS -> HTTP 429, AE-TMR-4029