These are production-tested Cloudflare Ruleset Engine expressions for the attack patterns DDactic most commonly finds unprotected. Each template includes the expression, the recommended threshold, the counting dimension, and the mitigation timeout. Adjust path expressions to match your application's actual endpoint structure.
Cloudflare plan requirements
Rate limiting rules via the Ruleset Engine require at minimum the Pro plan. Basic rate limiting is available on Free; advanced expressions (AND/OR, custom counting dimensions) require Business or Enterprise.
Template 1: Login Endpoint (Credential Stuffing)
# Expression scoped to POST on login paths
# Threshold: 5 requests per 60 seconds per IP
# Mitigation timeout: 10 minutes
Expression:
(http.request.uri.path contains "/login"
OR http.request.uri.path contains "/auth/token"
OR http.request.uri.path contains "/oauth/token")
AND (http.request.method eq "POST")
Action: Block
Threshold: 5
Period: 60
Mitigation timeout: 600
Counting expression: ip.src
Template 2: General API Rate Limit
# All requests under /api/ prefix
# Threshold: 200 requests per 60 seconds per IP
# Allows normal API usage while blocking sustained floods
Expression:
http.request.uri.path matches "^/api/"
Action: Block
Threshold: 200
Period: 60
Mitigation timeout: 300
Counting expression: ip.src
Template 3: Search Endpoint (Expensive Query Protection)
# Stricter limit on expensive search/query endpoints
# Threshold: 20 requests per 60 seconds per IP
Expression:
(http.request.uri.path contains "/search"
OR http.request.uri.path contains "/query"
OR http.request.uri.path contains "/find")
Action: Block
Threshold: 20
Period: 60
Mitigation timeout: 300
Counting expression: ip.src
Template 4: GraphQL Endpoint
# GraphQL endpoints need stricter limits due to query amplification
# Threshold: 30 requests per 60 seconds per IP
Expression:
(http.request.uri.path eq "/graphql"
OR http.request.uri.path eq "/api/graphql"
OR http.request.uri.path contains "graphql")
AND (http.request.method eq "POST")
Action: Block
Threshold: 30
Period: 60
Mitigation timeout: 300
Counting expression: ip.src
Template 5: Export and Report Endpoints
# Very expensive operations should have very low limits
# Threshold: 2 requests per 3600 seconds per IP
Expression:
(http.request.uri.path contains "/export"
OR http.request.uri.path contains "/report"
OR http.request.uri.path contains "/download")
Action: Block
Threshold: 2
Period: 3600
Mitigation timeout: 3600
Counting expression: ip.src
Template 6: Password Reset
# Password reset endpoints are targets for enumeration + DDoS
# Also triggers SMS/email costs at scale
Expression:
(http.request.uri.path contains "/password/reset"
OR http.request.uri.path contains "/forgot-password"
OR http.request.uri.path contains "/reset-password")
Action: Block
Threshold: 3
Period: 3600
Mitigation timeout: 3600
Counting expression: ip.src
Template 7: Bot Score Gating (Business/Enterprise)
# Challenge requests below bot score threshold on API paths
# This runs BEFORE rate limits to reduce legitimate traffic
# blocked by rate limits
Expression:
(http.request.uri.path matches "^/api/")
AND (cf.bot_management.score lt 10)
AND (not cf.bot_management.verified_bot)
Action: Managed Challenge
Rule Priority Ordering
Apply rules in this priority order (lower number = higher priority, evaluated first): 1) Bot score challenge on all API paths. 2) Login endpoint block (strictest). 3) Export/report block (very strict). 4) Search endpoint block (strict). 5) GraphQL block (strict). 6) General API block (permissive floor). Rules higher in the list fire before lower rules, so an IP blocked by rule 2 does not get re-evaluated against rule 6.
Verify Your Rules Are Working
DDactic tests your Cloudflare rate limit rules with calibrated request sequences to confirm they fire at the right thresholds.
Run a Free Scan