Reference

Rate limits and quotas on corsproxy.dev, explained

You got a 429. Here's exactly what counts against your quota, when it resets, and how the counter is enforced so you're never charged for someone else's overage — or let through past your own.

· ~4 min read

What counts as a request

Every authenticated call to /proxy (or /v1/proxy) that passes URL validation counts once, whatever the upstream returns. An upstream 500 and a clean 200 count the same — the meter runs on your request, not on whether the target liked it.

Requests rejected before that point don't count: a missing or invalid key, a malformed target URL, or a target on a private network blocked by SSRF protection.

Requests to account endpoints — /v1/auth/*, /v1/api-keys/*, /v1/usage/* — don't count against your proxy quota. Only actual proxying does.

How the limit is enforced

Your account's daily count lives in a Cloudflare Durable Object — one strongly-consistent counter per account, checked and incremented atomically on every request. That matters more than it sounds: a naive "read count, check, increment" implementation racing two simultaneous requests can let both through even when the first one alone should have hit the cap. A Durable Object serializes those checks, so the 100th request lands right on the limit and the 101st gets a 429, even under concurrent load.

Historical usage — the numbers behind your dashboard charts — is a separate, non-authoritative record in D1. It's what you see in Usage → History; it is not what gates your requests. The Durable Object is the only thing that can say yes or no in real time.

What a 429 looks like

HTTP/1.1 429 Too Many Requests

{
  "success": false,
  "error": "Rate limit exceeded. Your limit is 500 requests per day. Resets at Tue, 18 Aug 2026 00:00:00 GMT",
  "code": "RATE_LIMIT_EXCEEDED"
}

Successful proxy responses carry X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Used, and X-RateLimit-Reset (Unix seconds), so you can slow down before you hit the wall.

The counter resets at UTC midnight, not on a rolling 24-hour window. If you burn your quota at 11pm UTC, you get it back at midnight — not in 24 hours.

Limits by plan

Free tier is 500 requests/day per account, shared across all its keys. Paid tiers raise the ceiling; see API docs for current numbers, since those change independently of this post. Whatever your plan, the enforcement mechanism above is identical — there's no separate "trust me" path for paid keys, just a higher number.

If you're building something that needs more

Two honest options: request a higher limit (email [email protected] — we'd rather raise your quota than have you work around it), or self-host. The open-source core is the same proxy logic with no built-in ceiling — you set your own limits, or none.

What hitting your limit doesn't do

It doesn't ban your key or flag your account. It's purely a 429 until the counter resets — for every key on the account, since they share one quota. If you're seeing 429s you don't expect, check Usage → History in the dashboard first — the most common cause is a retry loop on the client side quietly multiplying real traffic.