Skip to main content
Security

Security limits

Reference limits for Easel firewall rules, Attack Mode, and related controls.

These limits describe current platform behavior that affects security configuration and challenge flows.

Attack Mode

LimitValue
Challenge response status429
Verification endpointPOST /.well-known/easel-challenge/verify
Session cookieeasel_ch_pass
Verification session lifetimeAbout 1 hour
Work-token lifetimeAbout 15 minutes

Challenge difficulty is platform-managed and may change.

Deployment protection

LimitValue
Session cookieeasel_dp
Session lifetimeAbout 1 hour

Request size

Large request bodies are rejected before they can exhaust edge or application resources. The default maximum request body size is 10 MiB unless otherwise configured for the platform.

Firewall rules

Custom rules are ordered per project. There is no separate priority number beyond list order.

Practical guidance:

  • Prefer fewer, well-scoped rules over many overlapping ones
  • Validate regex rules with Log before enforcing
  • Combine path and method conditions before broad IP or country denies

Plan-specific quotas for rule count, IP lists, and log retention may be published separately as product packaging evolves.

Geographic data

FieldSupport
CountrySupported in custom rules
ContinentSupported in custom rules
ASNSupported in custom rules
Region / cityNot available as firewall conditions

Geo and ASN data is powered by IPLocate.io (CC BY-SA 4.0). Accuracy can vary for VPNs, proxies, and mobile networks. Unknown locations do not match equality conditions unless you account for that explicitly.

Propagation

Firewall and Attack Mode configuration changes save on the project and propagate to the edge after a short delay. You do not need to redeploy. Allow a brief window before expecting every region to serve the latest rules.