# JWT claim based rate limiting

**URL:** <https://discuss.konghq.com/t/jwt-claim-based-rate-limiting/3935>\
**Category:** Questions\
**Created:** [July 8, 2019, 4:43pm UTC](https://discuss.konghq.com/t/jwt-claim-based-rate-limiting/3935 "2019-07-08T16:43:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Neil\_chambers](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/neil_chambers/32/1175_2.png) [@Neil\_chambers](https://discuss.konghq.com/u/Neil_chambers)\
**Post date:** [July 8, 2019, 4:43pm UTC](https://discuss.konghq.com/t/jwt-claim-based-rate-limiting/3935/1 "2019-07-08T16:43:47Z")

</div>

I have been asked to evaluate kong as a possible api gateway solution specifically with regards to effective rate limiting. In our case, we would like to rate limit individual customers, identified as a claim in a JWT bearer token.  
Is this kind of solution supported with one or more existing plugins or would we need to write one ourselves? I followed some links to enterprise documentation but didn’t find what I was looking for. I just need a pointer.

Cheers!

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [July 9, 2019, 1:11am UTC](https://discuss.konghq.com/t/jwt-claim-based-rate-limiting/3935/2 "2019-07-09T01:11:25Z")

</div>

You can use the JWT plugin for authentication purposes.

Then use the rate-limiting plugin to limit per consumer that is authentiated:

> **[Open-Source API Management and Microservice Management](https://docs.konghq.com/hub/kong-inc/rate-limiting/#parameters)**
>
> Secure, Manage & Extend your APIs or Microservices with plugins for authentication, logging, rate-limiting, transformations and more.

This is a very common use case for Kong.

---

<div class="post-metadata">

**Author:** ![Neil\_chambers](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/neil_chambers/32/1175_2.png) [@Neil\_chambers](https://discuss.konghq.com/u/Neil_chambers)\
**Post date:** [July 9, 2019, 7:16am UTC](https://discuss.konghq.com/t/jwt-claim-based-rate-limiting/3935/3 "2019-07-09T07:16:18Z")

</div>

Thanks 🙂  
My question was a little more specific - will the plugins allow me to use any claim from the JWT authentication token as a basis for rate limiting? In our case the subject of the JWT is not the Consumer.  
I’ll read up some more. Thanks again

---

<div class="post-metadata">

**Author:** ![Mju](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/mju/32/922_2.png) [@Mju](https://discuss.konghq.com/u/Mju)\
**Post date:** [June 23, 2022, 4:05pm UTC](https://discuss.konghq.com/t/jwt-claim-based-rate-limiting/3935/4 "2022-06-23T16:05:29Z")

</div>

is there a way to use any claim in the jwt token as the basis for rate limiting? @Neil_chambers
