Cloudflare Rate Limiting vs AWS WAF Rate-Based Rules vs Upstash Ratelimit: Real API Rate-Limiting Cost per 100 Million Requests in 2026
Prices checked: October 2, 2026.
Short answer
For 100 million API requests a month passing through a rate limiter:
| Option | Monthly cost | Label |
|---|---|---|
| Cloudflare, Free plan (1 rule, IP-based) | $0 | OFFICIAL |
| Cloudflare Pro / Business (2 / 5 rules) | $20–$25 / $200–$250 flat | OFFICIAL |
| Upstash Ratelimit on a fixed Redis plan | from $10 (if the plan's bandwidth and throughput fit) | ILLUSTRATIVE |
| AWS WAF rate-based rules (web ACL + 2 rules) | $67 | ILLUSTRATIVE from OFFICIAL rates |
| Upstash Ratelimit on pay-as-you-go | $400–$800 | ILLUSTRATIVE from OFFICIAL rates |
Cloudflare doesn't charge per request for rate limiting. Its plans just cap how many rules you get and how flexible they are. AWS charges for every request the web ACL inspects. Upstash charges per Redis command, and each rate-limit check costs 2 to 4 commands, so pay-as-you-go Upstash ends up the most expensive option here.
Native billing units
| Option | Billed on | Rate | Label |
|---|---|---|---|
| Cloudflare rate limiting rules | Plan per domain | Free: 1 rule, IP-only, 10 s max period. Pro: 2 rules, IP-only, up to 1 min. Business: 5 rules, IP and IP-with-NAT, up to 10 min. Enterprise: 100 rules; Advanced Rate Limiting adds header/cookie/JSON/path/JA3/JA4 counting | OFFICIAL |
| Cloudflare plans | Monthly | Pro $25 ($20 annual); Business $250 ($200 annual); Enterprise custom | OFFICIAL |
| AWS WAF | Web ACL, rules, requests | $5 per web ACL/month; $1 per rule/month; $0.60 per million requests inspected | OFFICIAL |
| Upstash Redis pay-as-you-go | Commands | $0.20 per 100,000 commands; 500K/month free; max 10,000 commands/s | OFFICIAL |
| Upstash Redis fixed plans | Plan | From $10/month (250 MB); no per-command billing; 10,000 commands/s; bandwidth caps (250 MB plan: 50 GB) | OFFICIAL |
| Upstash Ratelimit library | Redis commands per limit() call | Fixed window: 2 (3 first call). Sliding window: 4 (5 first call). Token bucket: 4. Denied requests served from local cache: 0 | OFFICIAL |
Upstash: commands per 100M requests (ILLUSTRATIVE)
| Algorithm | Commands per allowed request | Commands for 100M | Pay-as-you-go cost |
|---|---|---|---|
| Fixed window | 2 | 200M | $400 |
| Fixed window + analytics (+1) | 3 | 300M | $600 |
| Sliding window | 4 | 400M | $800 |
| Token bucket | 4 | 400M | $800 |
Pay-as-you-go math: commands ÷ 100,000 × $0.20. The 500K free commands are negligible at this volume. Requests denied from the in-memory cache cost 0 commands, so heavy abuse traffic can be cheaper than it looks.
A fixed plan changes the math. 100M requests a month averages about 39 requests/second, or 77–154 commands/second, far under the 10,000 commands/s cap. A fixed plan removes per-command billing entirely. The smallest one is $10/month but includes only 50 GB of bandwidth. At several hundred million small commands, check whether your traffic fits or needs a larger fixed tier.
Peak capacity. The 10,000 commands/s limit means a 4-command algorithm tops out around 2,500 rate-limit checks per second per database.
AWS WAF rate-based rules (ILLUSTRATIVE)
| Item | Calculation | Cost |
|---|---|---|
| Web ACL | 1 × $5 | $5 |
| Rate-based rules | 2 × $1 | $2 |
| Requests inspected | 100 × $0.60 | $60 |
| Total | $67 |
If you already run AWS WAF for security rules, the requests are already being paid for. Adding rate-based rules then costs only $1 per rule per month. The ALB, CloudFront or API Gateway the web ACL attaches to is billed separately.
Cost per million requests
| Option | $ per million requests |
|---|---|
| Cloudflare Free | $0 |
| Upstash fixed 250 MB plan (if it fits) | $0.10 |
| Cloudflare Pro (annual) | $0.20 |
| AWS WAF (standalone) | $0.67 |
| AWS WAF (rules added to an existing ACL) | ~$0.02 |
| Cloudflare Business (annual) | $2.00 |
| Upstash pay-as-you-go, fixed window | $4.00 |
| Upstash pay-as-you-go, sliding window | $8.00 |
Where the cost catches you
- Rule-count ceilings on Cloudflare. Free has 1 rule, Pro 2 and Business 5. Per-endpoint, per-API-key or per-tenant limits usually need Enterprise Advanced Rate Limiting (QUOTE-ONLY), because the lower plans count by IP only.
- AWS charges for inspection, not just limits. Every request the web ACL sees costs $0.60 per million, including the ones that pass.
- Upstash bills algorithm choice. Sliding window is smoother but doubles the commands compared with fixed window. Analytics, deny lists and dynamic limits add 1–2 commands each.
- Multi-region Upstash multiplies writes. Write commands are multiplied by (1 + read regions). Two read regions roughly triple the write-command bill.
- Edge vs origin. Cloudflare and AWS WAF block traffic before it reaches your servers. Upstash runs in your application code, so blocked requests still hit your compute, just not your business logic.
Which one fits
- IP-based protection at the edge, lowest cost: Cloudflare Free or Pro.
- Already on AWS WAF: add rate-based rules for $1 each.
- Per-user, per-API-key or per-plan quotas inside your app: Upstash Ratelimit on a fixed plan, which is cheap and flexible. On pay-as-you-go, use fixed window with caching to keep commands down.
- Complex edge rules keyed on headers, JSON fields or fingerprints: Cloudflare Enterprise Advanced Rate Limiting. Expect a sales quote.
Assumptions
- 100,000,000 requests/month; nearly all requests allowed (worst case for Upstash command counts)
- Upstash single-region database; AWS us-east-1; Cloudflare self-serve plans
- Excludes underlying compute, load balancers and taxes
Pricing sources
- Cloudflare rate limiting rules: https://developers.cloudflare.com/waf/rate-limiting-rules/
- Cloudflare plans: https://www.cloudflare.com/plans/
- AWS WAF pricing: https://aws.amazon.com/waf/pricing/
- Upstash Redis pricing: https://upstash.com/pricing/redis
- Upstash Ratelimit command costs: https://upstash.com/docs/redis/sdks/ratelimit-ts/costs