Skip to content

feat: Make request budgets configurable - #133

Open
SamyPesse wants to merge 2 commits into
workos:mainfrom
SamyPesse:codex/configurable-request-budget
Open

SamyPesse wants to merge 2 commits into
workos:mainfrom
SamyPesse:codex/configurable-request-budget

Conversation

@SamyPesse

@SamyPesse SamyPesse commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

The fixed 1,000-request budget can throttle larger integration suites sharing one API key, causing SDK retries to wait for the next window. Add a positive-safe-integer requestsPerMinute option to createEmulator and the core server options, retaining the default of 1,000.

Each 60-second window now accepts the full configured budget. A budget of 1 permits one request; the last accepted request reports X-RateLimit-Remaining: 0, and subsequent requests receive HTTP 429 with Retry-After until the window resets. This addresses Greptile's smallest-budget finding and corrects the same boundary for default and larger budgets. The README documents configuration, headers, and window behavior.

Validation:

  • All 1,354 upstream tests pass, including 10 HTTP regression cases covering exact budget boundaries, API-key isolation, repeated exhaustion, the exact 60-second reset, larger budgets, and invalid options. The new boundary regressions reproduced the bug before the fix.
  • Build, type checks, lint, formatting, Node compatibility smoke, and package validation pass.
  • The branch is based on the latest upstream main (c63466f246b5060c766df4155676784543c7e171).
  • The downstream patch for published @workos/emulate@0.14.0 matches the four built runtime/type files byte for byte. A fresh frozen-lockfile installation, OpenKnowledge Compute's bun run check, all 22 backend integration scenarios, and the 10 HTTP regression cases against the installed patched package pass.

@SamyPesse SamyPesse changed the title Make request budgets configurable feat: Make request budgets configurable Oct 9, 2026
@SamyPesse
SamyPesse marked this pull request as ready for review October 9, 2026 15:03
@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium impact] The PR appears safe to merge; the smallest-budget bug is fixed and no new actionable issues were found.

Summary

Adds requestsPerMinute to createEmulator and ServerOptions, keeping the default at 1,000.

  • Requires a positive safe integer.
  • Fixes the counter so the full configured budget is accepted, including a budget of 1.
  • Adds tests for accepted requests, exhausted budgets, separate API keys, and window resets.
  • Updates the README to explain local rate limiting.

Reviews (2) · Last reviewed commit: "Accept the full configured request budge..." · Reviewed by Greptile

Comment thread src/core/server.ts
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant