NewWe open-sourced 50+ Laravel packages
Custom AI apps, agents and automation — Roundly ConsultingRoundly
All packages

Useful when a single quota is shared across servers or accounts and you want each owner tracked separately (e.g. per outbound IP). by() scopes every window the limit enforces, compound ones included:

$middleware = RateLimits::perHour(60)->by('203.0.113.10');

Http::withMiddleware($middleware)->get('https://api.example.com/orders');

The macro takes the same owner as a named argument — Http::rateLimit(30, by: 'acct-1') — and it works with every form: an integer, a profile name, a RateLimit, a Limit or a compound array, where it scopes every window. It re-keys a copy, so a RateLimit or Limit you pass in (and reuse elsewhere) keeps its own key.

Keep upstream APIs apart

Hits are stored per owner key and window. A limit without by() uses the key global, and every limit records into one shared store, so two unrelated limits without a key on the same window read the same hit history. Give each API — and each tenant, when budgets are per customer — its own key:

// Without by(), every limit uses the owner key 'global'. Every limit shares one
// store, so give each upstream API its own key so their budgets never mix:
$github = RateLimits::perSecond(5)->by('github');
$stripe = RateLimits::perSecond(25)->by('stripe');

// Per-tenant budgets for the same API:
Http::rateLimit(RateLimits::perMinute(100)->by("billing:{$tenant->id}"))
    ->post('https://api.example.com/invoices', $payload);

Show your open-source love

This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.

More ways to support, including crypto

By donating, you agree to our donation terms.

Want this built into your product?

We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.