All Tools View Categories About Contact Privacy

Nginx Rate Limiting Config Generator (limit_req)

Throttle abusive traffic with a request-rate limit zone.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your rate limiting config will appear here.
-
lines
-
blocks
-
locations

About Nginx Rate Limiting Config Generator (limit_req)

Rate limiting is the first line of defence against brute force, scrapers and accidental request floods, and nginx does it beautifully with limit_req. The trap is that the zone lives in the http context while the limit is applied in a location, and getting the rate string or the burst keyword wrong silently breaks the protection. The Nginx Rate Limiting Config Generator wires both pieces together with a validated rate, burst and nodelay, then checks its own output.

At the heart of the configuration are a handful of directives. limit_req_zone defines a shared memory zone keyed by client IP and a request rate, placed in the http context. limit_req applies the named zone inside a location, throttling requests that exceed the rate. burst permits a short queue of excess requests instead of rejecting them outright. nodelay serves bursted requests immediately rather than spacing them out at the rate. server the virtual host that references the rate limit zone. location the path scope where the limit is enforced. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. The zone must be declared in http but the limit in a location; splitting them across files by mistake disables protection, so the tool emits both. A malformed rate like "10/s" is rejected because nginx expects the r/s or r/m form, so the generator validates the unit. Using nodelay without a sensible burst can let spikes through, while omitting nodelay can add latency; the tool makes the choice explicit. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

For teams, a generated block is also documentation. New engineers can read the exact directives in place, compare them against the sample, and learn the relevant nginx behaviour without reverse-engineering a hand-maintained file that drifted from its original intent.

Features

  • limit_req_zone - defines a shared memory zone keyed by client IP and a request rate, placed in the http context.
  • limit_req - applies the named zone inside a location, throttling requests that exceed the rate.
  • burst - permits a short queue of excess requests instead of rejecting them outright.
  • nodelay - serves bursted requests immediately rather than spacing them out at the rate.
  • server - the virtual host that references the rate limit zone.
  • location - the path scope where the limit is enforced.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Name the rate limit zone.
  2. Set the shared memory size (e.g. 10m).
  3. Enter the rate as count per second or minute.
  4. Set a burst allowance.
  5. Decide whether to use nodelay.
  6. Enter the domain and location path to protect.
  7. Click Generate (or Load sample) and review the config.

Examples

Example 1 - Login throttling 10r/s with burst 20 and nodelay on a login location.

Example 2 - API cap 100r/m on an api path to bound third-party callers.

Example 3 - Delayed burst burst 10 with nodelay off so excess is paced, not rejected.

Example 4 - Big zone 20m zone for a busy site with many distinct clients.

Example 5 - Bad rate rejected a rate without r/s or r/m is reported before generation.

Benefits

  • Zone and location emitted together correctly.
  • Rate string validated for r/s and r/m.
  • Burst and nodelay made explicit.
  • Per-IP key using compact binary form.
  • Self-checked output re-parsed before display.
  • Private: everything runs in your browser.

Frequently Asked Questions

What does the zone do?
limit_req_zone allocates a shared memory zone that tracks request rates per key, here the client IP, across all workers.
What is burst?
Burst allows a client to exceed the rate briefly by queuing up to N requests instead of rejecting them immediately.
What does nodelay do?
Without nodelay, bursted requests are served at the configured rate (delayed). With nodelay they are served immediately up to the burst limit.
Why key on $binary_remote_addr?
It identifies clients by IP using a compact binary form, saving memory in the shared zone compared to the string $remote_addr.
Will this stop all abuse?
It slows request floods and brute force, but determined distributed attacks need a WAF or upstream mitigation too.
Can I limit only some paths?
Yes - the limit_req directive is placed inside the specific location you want throttled.
Is the output validated?
Yes - the config is re-parsed by a built-in tokenizer before display.
Is anything uploaded?
No. Everything runs in your browser.