Rate limits

Set how many requests your Burrow accepts from each address, in total, and for share links, excuse networks you trust, and see who is being refused.

Updated Oct 8, 2026

The Rate limits section under Settings decides how many requests your Burrow accepts, and shows what it has refused. Each limit sits on its own card with its settings and how many requests it has allowed and refused since the Burrow started. Below the cards are the addresses locked out, the addresses refused in the last hour, and the latest refusals. The page updates on its own as requests are refused.

Viewing the section needs permission to read the Burrow's configuration. Changing a limit or adding an exempt network needs permission to change it, and lifting a lockout or removing an exempt network needs permission to delete.

Changing a limit#

Each limit has a Rate, the requests per second it accepts over time, and a Burst, how many requests can arrive at once on top of that. Enter the new values on the card and select Save. Each card saves on its own. Reset to defaults appears on a card whose values differ from the built-in ones and puts those back in the boxes, ready to save.

A saved limit applies from the next request, with nothing to restart. Every address starts the new limit with its full burst, and addresses already locked out stay locked out.

Per address#

Everything one IP address sends: the dashboard in a browser, machines reading secrets through the CLI or an SDK, and share pages. The default is 50 requests a second with a burst of 100. The rate can be 1 to 5,000 a second and the burst 1 to 20,000.

Machines behind one NAT or egress address share that address's limit. If a fleet like that gets refused, raise this limit or add its address under Exempt networks.

Whole Burrow#

All requests from every address together, the most your Burrow takes in at once. The default is 1,000 requests a second with a burst of 2,000. The rate can be 10 to 20,000 a second and the burst 10 to 100,000, and neither can be lower than the per-address limit.

Opening a share link, counted per address. Opening a link that has a passphrase checks that passphrase, so this limit is what keeps someone from guessing it. By default it accepts 1 request a second with a burst of 16, and an address refused 20 times within an hour is locked out of share links for 15 minutes.

Lock out after sets how many refusals within an hour lock an address out, from 2 to 1,000, and Lock out for sets how long the lockout lasts, from 1 to 1,440 minutes. The rate can be 1 to 100 a second and the burst 1 to 1,000.

Exempt networks#

The Per address card lists addresses the per-address limit skips, such as your office or a fleet's NAT address. Enter a single address such as 203.0.113.4 or a range in CIDR form such as 10.0.0.0/8, add an optional label, and select Add. A range is stored in its canonical form, so 10.1.2.3/8 is saved and matched as 10.0.0.0/8. Remove an entry with the cross on its chip.

An exempt address still counts toward the whole-Burrow limit, and share links still limit it. Adding or removing an entry applies from the next request.

Refused requests and lockouts#

Below the cards, Counted since gives the time the Burrow started, which is when the counts on the cards began.

Locked Out lists each address under a lockout, which limit it is locked out of, and until when. Select Lift to end a lockout early. Lifting also forgets the address's earlier refusals, so its next refusal doesn't lock it out again straight away.

Refused in the Last Hour lists the addresses refused most, with how many of their requests were refused, by which limit, and when last. An address shows where it is when IP location data is on in Burrow config, and the name of the machine that last called from it, if any. Select Exempt on a row to add that address to Exempt networks in one step, labelled with the machine's name when there is one.

Latest Refusals shows the 20 most recent refused requests: the path asked for, the address, the limit that refused it, and when. A request refused because its address was locked out is marked Locked out.

What a refused request gets#

A refused request gets a 429 Too Many Requests response with a Retry-After header giving the seconds to wait before trying again. A script or application that gets one is sending faster than its limit allows.

In the audit log#

Refused requests are recorded as ratelimit.refused, one entry per limit and address for each minute that had refusals, with how many there were. A lockout starting is recorded as ratelimit.lockout, and lifting one as ratelimit.lockout.lift. Changing a limit is recorded as ratelimit.change, adding and removing exempt networks as ratelimit.exempt.add and ratelimit.exempt.remove, and opening the page as ratelimit.view. Webhooks can send any of them as they happen.

Rate limits belong to this machine's network, so restoring a backup leaves them as they are.