rl-js-client

Security Policy

Reporting Security Issues

Please do not report security vulnerabilities through public GitHub issues.

If you believe you have found a security vulnerability in the RateLimitly JavaScript client, please report it via email to:

wojciech@ratelimitly.com

Please include:

You will receive an acknowledgment within 48 hours and regular updates on remediation progress.


Credential & Secret Handling

RateLimitly Bech32 API keys (rl-cookie..., rl-aes...) contain embedded authentication secrets:


Authentication Modes & Threat Model

Mode Format Prefix Confidentiality Packet Integrity Replay Protection Recommended Deployment
AES-256-GCM rl-aes1... Encrypted PDU Yes (Authenticated Data) Bound to GCM Tag Public & Multi-Tenant Networks
Cookie rl-cookie1... Plaintext No Plaintext Match Private / VPC Networks Only
None rl-none1... Plaintext No Plaintext Match Local / Testing Only

AES-256-GCM Mode


Response Replay & Correlation Boundary


Supported Versions

Version Supported Notes
1.0.x ✅ Yes Active release branch (Format v1 packed quotas & HA policy)
< 1.0.0 ❌ No Pre-release