Prompt
AWS API Gateway throttling by tenant
Latest observation
If you need AWS API Gateway throttling by tenant, the key point is:
- API Gateway’s native throttling is not tenant-aware by itself unless tenants map cleanly to things API Gateway can distinguish, like:
- API keys / Usage Plans
- Authorizer context + custom logic
- Separate stages/domains/accounts
- A custom rate limit layer in front of your backend
Common approaches
1) Use API keys + Usage Plans
Best if each tenant can have its own API key.
- Create a unique API key per tenant
- Attach the key to a Usage Plan
- Set:
- rate limit (steady requests per second)
- burst limit
- API Gateway enforces throttling per key
Pros
- Simple
- Native support
- Easy to audit
Cons
- Only works if tenants can be identified by API key
- Not ideal for end-user identity unless you control client provisioning
2) Throttle in your application using tenant identity
Best if tenants are identified by:
- JWT
tenant_id - Cognito claim
- Custom authorizer context
- Header like
X-Tenant-Id
Then implement per-tenant rate limiting in:
- Lambda middleware
- Backend service
- Redis/DynamoDB-based limiter
- API Gateway Lambda authorizer + backend enforcement
Typical design
- API Gateway authenticates request
- Authorizer extracts tenant ID
- Backend checks rate limit in Redis/DynamoDB
- If exceeded, return
429 Too Many Requests
Pros
- Truly tenant-aware
- Flexible policies per tenant
- Can support tiered plans
Cons
- You must build/operate the limiter
- Not enforced directly by API Gateway
3) Use WAF rate-based rules
Good for protecting against abusive traffic, but not ideal for per-tenant throttling unless tenant identity is visible in something you can match on.
AWS WAF rate limits are usually better for:
- IP-based abuse protection
- Broad traffic shaping
Limitation
- Not a precise tenant quota system
4) Separate tenants by API key + custom usage tiers
If you have different tenant plans:
- Free tenants get smaller usage plan
- Premium tenants get larger usage plan
This is often the cleanest “tenant throttling” solution when tenants are external customers.
Recommended architecture
If tenants are authenticated users/customers, the most robust pattern is:
- API Gateway
- JWT/Cognito/custom authorizer
- Extract
tenant_id - Redis or DynamoDB rate limiter
- Backend service
Use API Gateway usage plans only when API key-based tenancy fits your model.
If you want native AWS-only throttling
Then your best option is:
- API key per tenant
- Usage Plan per tenant or per tenant tier
That’s the closest thing to “API Gateway throttling by tenant” without custom code.
If you want, I can give you:
- a reference architecture
- a Terraform/CloudFormation example
- a Lambda + Redis rate limiter implementation
- or help choose the best design for your tenant model.