# Rate limit for 200 success responses only

**URL:** <https://discuss.konghq.com/t/rate-limit-for-200-success-responses-only/11755>\
**Category:** General\
**Tags:** kong-gateway\
**Created:** [August 7, 2023, 3:53am UTC](https://discuss.konghq.com/t/rate-limit-for-200-success-responses-only/11755 "2023-08-07T03:53:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![answerquest](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/answerquest/32/4035_2.png) [@answerquest](https://discuss.konghq.com/u/answerquest)\
**Post date:** [August 7, 2023, 3:53am UTC](https://discuss.konghq.com/t/rate-limit-for-200-success-responses-only/11755/1 "2023-08-07T03:53:45Z")

</div>

I’m using rate-limiting plugin and limiting by credential (which is determined by api key, key-auth plugin is active). That’s working fine. Now, I noticed that even error responses like 400, 502 etc are getting counted towards the quota I’ve set; not just the 200 success ones. What should I do to make the rate limit plugin enforce only for success responses? I don’t want a wasted api call getting counted towards the quota.

I’m on Kong gateway dockerized 3.3.0, the free / community one.

---

<div class="post-metadata">

**Author:** ![VJ316](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/vj316/32/4068_2.png) [@VJ316](https://discuss.konghq.com/u/VJ316)\
**Post date:** [August 7, 2023, 12:18pm UTC](https://discuss.konghq.com/t/rate-limit-for-200-success-responses-only/11755/2 "2023-08-07T12:18:38Z")

</div>

I have not seen anything in the rate limiting plugin to modify the quota against a particular status code yet.  
Even if we can achieve a functionality like this using something like a custom plugin, this will leave our API vulnerable to DDoS attacks since we are allowing practically unlimited requests for invalid requests.

---

<div class="post-metadata">

**Author:** ![trustworthygoblin](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/trustworthygoblin/32/4395_2.png) [@trustworthygoblin](https://discuss.konghq.com/u/trustworthygoblin)\
**Post date:** [August 10, 2023, 3:18pm UTC](https://discuss.konghq.com/t/rate-limit-for-200-success-responses-only/11755/3 "2023-08-10T15:18:44Z")

</div>

@VJ316 +1.  
Besides status codes such as 4xx are API user level errors something clients should be wary of, while 5xx are internal API errors which should not occur or should be fixed immediately.

---

<div class="post-metadata">

**Author:** ![answerquest](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/answerquest/32/4035_2.png) [@answerquest](https://discuss.konghq.com/u/answerquest)\
**Post date:** [August 11, 2023, 5:23am UTC](https://discuss.konghq.com/t/rate-limit-for-200-success-responses-only/11755/4 "2023-08-11T05:23:14Z")

</div>

Hi,  
Thanks a lot for your inputs. I agree with the opinion that it’s not practical to do rate limiting based on response.

If we do go to implement this, I reckon I’ll need one wider rate limit in Kong; and then in the application backend will have to put limits on number of successes in a day etc as per business logic.
