NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2331 most downloaded on npm
A generic rate limiter for the web and node.js. Useful for API clients, web crawling, or other tasks that need to be throttled
Last release 24 days ago
11 Sep 2026
Release timing varies
gaps range from 3 weeks to 3.7 years
Most releases are documented
notes for 17 of 19 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
19 releases · first in 2012
Add RateLimiter.getWaitTime(count) to estimate cooldowns across both the bucket and interval allowance ( #88 ).
RateLimiter.getWaitTime(count) to estimate cooldowns across both the bucket and interval allowance (#88).limiter@4.0.0 fixes concurrent rate-limit accounting, atomic parent/child debits, and bounded FIFO waiting. It is a major release because invalid nume
limiter@4.0.0 fixes concurrent rate-limit accounting, atomic parent/child debits, and bounded FIFO waiting. It is a major release because invalid numeric inputs now reject and request ordering changes.
Before upgrading, review the 3.x migration guide. Check configuration for negative, non-finite, or unsafe token values; handle rejected asynchronous calls; and account for FIFO head-of-line waiting. Remaining fractional balances may differ slightly due to improved clock precision.
No runtime dependencies are added. Both CommonJS and ESM distributions remain available. The npm archive now includes the changelog and excludes tests and TypeScript build caches.
Validation: all 27 tests, lint, both builds, and CommonJS/ESM imports from the packed package passed locally; CI covers Node 20, 22, and 24.
One column per quarter.
This is a major release because input validation and asynchronous request ordering change observable behavior. See Upgrading from 3.x before upgrading.
RangeError (or reject the returned promise).Dual Module Support: Distributed as both CommonJS and ES Module, with separate package.json files for each format (no need for custom transformers). T
package.json files for each format (no need for custom transformers). This improves compatibility with modern bundlers and frameworks.just-performance dependency in favor of Node’s built-in high-resolution timers. Timing now relies on process.hrtime/performance APIs, ensuring monotonic behavior without external packages."type": "module" from the main package and the introduction of a dedicated ESM build fix the ERR_MODULE_NOT_FOUND and Unexpected token errors in Node 16+.Compatibility Improvements: Incorporated changes to better support modern JavaScript environments. Internal logic now accommodates bundlers and strict
just-performance to v4.3.0, aligning with Node.js improvements."type": "module" field from package.json to treat the package as CommonJS by default. This change improves compatibility with Webpack 5 and others that encountered issues loading the library in 2.0.x..js extensions where required for ESM compliance (no more “Cannot find module” errors when using ESM).ESM Usage Bugs: Patched minor issues following the 2.0.0 rewrite. Specifically, ensured that all internal module imports include file extensions (nece
Callback API: Removed all deprecated callback parameters in favor of promises. Callbacks are no longer invoked or supported in any methods.
.d.ts declarations.removeTokens now return a Promise that resolves when tokens are removed (or rejects on error), allowing async/await usage.RateLimiter.removeTokens() and related methods no longer accept Node-style callbacks. Instead, they return Promises. For example: await limiter.removeTokens(5) replaces the old limiter.removeTokens(5, callback).RateLimiter constructor signature changed. Instead of positional parameters, it now takes a single options object (e.g. { tokensPerInterval, interval, fireImmediately }). This improves clarity but may require updates to existing initialization code.Type Definitions Update: Improved the bundled TypeScript definitions for the library. The community-contributed update (PR #62) refines the types for
RateLimiter and TokenBucket to better reflect the library’s API and usage (e.g., marking asynchronous methods as returning Promises, etc.).`tryRequestTokens` Bug: Fixed an error in the tryRequestTokens function (introduced in 1.1.3). The bug could cause exceptions or incorrect behavior wh
tryRequestTokens Bug: Fixed an error in the tryRequestTokens function (introduced in 1.1.3). The bug could cause exceptions or incorrect behavior when using tryRemoveTokens/tryRequestTokens. This release ensures that attempting to remove tokens without waiting works as intended without throwing errors.Monotonic Clock Support: Rate limiting now uses a monotonic clock for tracking intervals. Where available, the library uses process.hrtime instead of
process.hrtime instead of the system clock (Date). This prevents issues if the system time is changed (e.g., NTP adjustments).interval option string. If an invalid interval string is provided, an error is thrown immediately (PR #43). This helps catch misconfigurations early.remainingRequests (in README) was updated to reflect the actual behavior (PR #31).Typings in Package: The TypeScript declaration file (index.d.ts) is now included in the published package. This means TypeScript users get typings aut
index.d.ts) is now included in the published package. This means TypeScript users get typings automatically when installing the package (PR #40)..d.ts file wasn’t packaged, causing TS consumers to have no types. This release fixes that by adding it to the package.json “files” whitelist."second", "minute", "hour", and "day" are accepted for the interval option everywhere. (These were documented before, but this release unified support across code and types).TypeScript Definitions: Added official TypeScript type definitions for the library. The project now ships with an index.d.ts file describing the API,
index.d.ts file describing the API, thanks to PR #31 and #39.RateLimiter.tryRemoveTokens() did not increment the internal tokensThisInterval counter. This bug could allow over-consuming tokens within a single interval. After this fix, token removal via tryRemoveTokens properly counts toward the per-interval limit.Bower Support: Introduced a bower.json file for front-end usage. This allows the library to be installed via Bower for browser-based projects (no chan
bower.json file for front-end usage. This allows the library to be installed via Bower for browser-based projects (no changes to core functionality).`tryRemoveTokens()` (Sync Removal): Introduced a new synchronous method tryRemoveTokens(count) on both RateLimiter and TokenBucket. This method attemp
tryRemoveTokens() (Sync Removal): Introduced a new synchronous method tryRemoveTokens(count) on both RateLimiter and TokenBucket. This method attempts to remove the requested number of tokens and returns immediately with a boolean indicating success or failure. It allows token checks/removals without using a callback.tryRemoveTokens() and its usage. Also clarified existing docs where necessary (no API changes besides the new method).Stale Token Count: Resolved an issue with RateLimiter.getTokensRemaining(). It now calls tokenBucket.drip() before reporting the remaining tokens, so
RateLimiter.getTokensRemaining(). It now calls tokenBucket.drip() before reporting the remaining tokens, so the returned count accounts for tokens added over time. Previously, under certain conditions, getTokensRemaining() could return an outdated number if no tokens had been removed recently (PR #6).`getTokensRemaining()` Method: Added a new helper method RateLimiter.getTokensRemaining() to retrieve the number of tokens left in the current interva
getTokensRemaining() Method: Added a new helper method RateLimiter.getTokensRemaining() to retrieve the number of tokens left in the current interval outside of the removeTokens callback. This allows users to check remaining capacity at any time (PR #4 by @mluto).getTokensRemaining() and general usage notes.Nothing published for this version
Immediate Callback Option: Added support for firing the callback immediately when rate limiting is in effect. A new boolean option fireImmediately can
fireImmediately can be passed to RateLimiter to have removeTokens() call the callback right away with a negative remaining count when the limit is exceeded. This allows the calling code to handle rate-limit events without waiting for the interval reset.RateLimiter will not allow more tokens to be removed in a given interval than the tokensPerInterval limit. Previously, under certain usage patterns, it was possible to schedule removals that exceeded the interval cap. The internal counter tokensThisInterval is now properly utilized to cap removals, preventing over-consumption within a single interval.fireImmediately option usage and clarified the behavior when the rate limit is reached (e.g., remaining tokens can be negative if fireImmediately is true).Initial Release: Introduced the core functionality of the rate limiter.
tokensPerInterval (number of tokens) and interval (length of each interval, in ms or as "second", "minute", "hour", "day"). Optionally, fireImmediately can be set to control callback timing.Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →