RFC 130: Upcoming changes to invocation rate limits

Hello everyone,
Thanks again for all of the feedback on RFC‑130! Your input has helped us finalise a solution that addresses most of the use cases discussed here. As there are no further comments, we’ll be closing this RFC for discussion, and proceeding with the discussed solution.
What did we hear?

  • Per-user rate limiting is valuable for protecting against DDOS attacks and is something partners prefer be maintained by the Forge platform

  • Dynamic rate limiting provides more flexibility for large apps and growth

  • Partners want visibility on rate limiting behaviour in all invocation responses

What do we intend to tackle later?
We will continue evaluating the need for dynamic rate limiting and explore an implementation if the need arises.

What is coming next?
We will roll-out changes to include rate limiting information on all invocation types addressed by this RFC, namely user-initiated invocations such as web triggers and UI invocations. These changes will be announced on the Forge changelog.

Following this, we will roll-out changes to the invocation limits in July, following a 3-month notice period from the release of this RFC.