/** * Per-key token-bucket rate limiter for inbound /v1/* requests. * * Bounds api-key-id enumeration (the v0.40 follow-up noted in auth.ts): a * client that drains its bucket is denied until it refills. Dependency-free * and unit-testable in isolation via the injectable `now`. */ export interface RateLimiter { /** * Consume one token for `key`. Returns true if the request is allowed, * false if the key's bucket is exhausted. `now` (epoch ms) is injectable * for deterministic tests. */ check(key: string, now?: number): boolean; } export interface RateLimiterOpts { /** Sustained refill rate in tokens per second. */ ratePerSec: number; /** Bucket capacity — the largest burst a fresh client may spend at once. */ burst: number; /** A bucket untouched for this many ms is dropped by the throttled sweep. */ idleEvictMs: number; /** Hard cap on tracked keys; the least-recently-used key is evicted on overflow. */ maxKeys: number; } /** * Build a token-bucket limiter. Memory is bounded two ways: a sweep (throttled * to once per `idleEvictMs`) drops idle buckets, and a hard `maxKeys` cap evicts * the least-recently-used key, so a client rotating source addresses cannot * grow the map without bound between sweeps. */ export declare function createRateLimiter(opts: RateLimiterOpts): RateLimiter; //# sourceMappingURL=rate-limit.d.ts.map