Prompt
Kong auth and rate limit setup
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Here’s a practical Kong auth + rate limiting setup you can use as a starting point.
1) Typical plugin order
Common setup for a protected API:
- Authentication
key-auth,jwt,oauth2,openid-connect, etc.
- Rate limiting
rate-limitingorrate-limiting-advanced
- Optional: logging/monitoring plugins
Kong evaluates plugins by phase, so auth happens before rate limiting in most cases.
2) Example: Key Auth + Rate Limiting
Enable key auth on a service or route
curl -i -X POST http://localhost:8001/services/my-service/plugins \
--data "name=key-auth"
Add rate limiting
curl -i -X POST http://localhost:8001/services/my-service/plugins \
--data "name=rate-limiting" \
--data "config.minute=100" \
--data "config.policy=local"
3) Create a consumer and key
curl -i -X POST http://localhost:8001/consumers \
--data "username=client1"
curl -i -X POST http://localhost:8001/consumers/client1/key-auth \
--data "key=my-secret-key"
4) Call the API
curl -i http://localhost:8000/my-api \
-H "apikey: my-secret-key"
If the key is valid, Kong forwards the request. If not, it returns 401.
5) Example with JWT auth
Enable JWT
curl -i -X POST http://localhost:8001/services/my-service/plugins \
--data "name=jwt"
Add rate limiting
curl -i -X POST http://localhost:8001/services/my-service/plugins \
--data "name=rate-limiting" \
--data "config.minute=100"
Configure consumer with JWT credential
curl -i -X POST http://localhost:8001/consumers \
--data "username=client1"
curl -i -X POST http://localhost:8001/consumers/client1/jwt \
--data "key=client1" \
--data "secret=my-jwt-secret"
Then send a signed JWT in the request.
6) Recommended production considerations
- Use
rate-limiting-advancedif you need better controls - Prefer Redis policy for distributed Kong deployments
- Apply plugins at the route level if only some endpoints need protection
- Add ACL plugin if you want consumer group-based access
- If using OIDC,
openid-connectis usually the cleanest option
7) Best practice example
For a public API:
openid-connectfor authrate-limiting-advancedfor quota controlcorsif browser clients access itrequest-size-limitingto reduce abuse
If you want, I can also give you:
- a Kong declarative config (
kong.yaml), - a Kubernetes Ingress / Kong Ingress Controller setup, or
- a Docker Compose demo for auth + rate limiting.