Skip to content
You are reading the v2 docs, currently in beta.V1 docs
oRPC
Esc
↑↓navigate↵open⌘Jpreview
On this page

Request Limit Plugin

Restrict the size of incoming request bodies with RequestLimitHandlerPlugin to protect your server from oversized payloads.

Setup

Use RequestLimitHandlerPlugin to limit the size of incoming request bodies.

import { RequestLimitHandlerPlugin } from '@orpc/server/plugins'

const handler = new RPCHandler(router, {
  plugins: [
    new RequestLimitHandlerPlugin({
      /**
       * The maximum allowed request body size in bytes.
       */
      maxBodySize: 1024 * 1024, // 1MB
    }),
  ],
})

Peer Adapters

This plugin does not apply to peer-based adapters such as WebSocket and Message Port. Each message reaches the handler fully loaded in memory, so there is no body left to limit. Instead, limit each message at the transport, and the total bytes per connection per minute, since a single call can span many messages (for example, an AsyncIteratorObject input). With Bun:

const MAX_BYTES_PER_MINUTE = 10 * 1024 * 1024 // 10MB
const usage = new WeakMap<object, { bytes: number, resetAt: number }>()

Bun.serve({
  websocket: {
    maxPayloadLength: 1024 * 1024, // 1MB per message, larger messages close the connection
    async message(ws, message) {
      let entry = usage.get(ws)
      if (!entry || Date.now() >= entry.resetAt) {
        usage.set(ws, entry = { bytes: 0, resetAt: Date.now() + 60_000 })
      }

      entry.bytes += Buffer.byteLength(message)

      if (entry.bytes > MAX_BYTES_PER_MINUTE) {
        ws.close(1008, 'Too much data per minute')
        return
      }

      await handler.message(ws, message)
    },
    async close(ws) {
      await handler.close(ws)
    },
  },
})

Other WebSocket servers have an equivalent per-message option, such as maxPayload in ws.

Learn More

For implementation details, see the source code.

Last updated on October 4, 2026

Was this page helpful?