wso2 / wso2/api-platform

[Bug]: Advanced Rate Limit not applying globally even when defined globally

Open
#2,506 0 comments 0 reactions 1 assignee View on GitHub

@renuka-fernando is already working on this.

Since Jul 7, 2026.

Area/Management Aspect/API Severity/Major Type/Bug
Dominant language
Go
Stars
71
Forks
111
Avg merge
1d 14h
Merged PRs (30d)
110

Description

Please select the area the issue is related to

Area/Management (Management API or Management Portal UI)

Please select the aspect the issue is related to

Aspect/API (API backends, definitions, contracts, interfaces, OpenAPI)

Description

When advanced-ratelimit policy is configured at an API-level, without specifying the keyExtraction as apiname, it is default to resource level leading it to act as though a resource-level ratelimit policy.

Steps to Reproduce
  1. Create LLM Proxy
  2. Attach global rate-limit policy via the rate-limit configuring tab in the AI Workspace/ advanced-rate-limit policy via the Guardrails & Policies tab.
  3. Deploy and invoke to verify the ratelimiting
Severity Level of the Issue

Severity/Major (Important functionality is broken. Should be prioritized. Doesn't need immediate attention)

Environment Details (with versions)

No response

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.