Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To protect a screenshot endpoint, create a zone-level Cloudflare rate-limiting rule in the http_ratelimit phase entry-point ruleset and scope it to the endpoint’s host and path. Set the counter identity, request threshold, period, and mitigation to fit your traffic. Do not copy Cloudflare’s API-wide quota or a documentation example as your application’s threshold: Cloudflare API quotas, Browser Rendering REST quotas, and your WAF rule are three separate controls.

Which Cloudflare limit are you configuring?

“Cloudflare API rate limit” can mean either a quota Cloudflare enforces on calls you make to Cloudflare, or a WAF rule you configure to control incoming requests to a website in a Cloudflare zone. For a screenshot route on your own site, the WAF rate-limiting rule is usually the control you want.

Control What it limits Applies to your screenshot route?
Cloudflare client API quota Calls made to Cloudflare’s APIs. Cloudflare’s API limits page, last updated Aug. 25, 2026, lists 1,200 requests per five-minute period per user/account token and a separate 200 requests per second per IP limit. The global token quota is cumulative across dashboard, API key, and API-token activity. Cloudflare API limits No. This governs your management/API calls to Cloudflare, not visitors requesting screenshots from your application.
Browser Rendering REST quota Requests to Cloudflare Browser Rendering REST endpoints. In a March 4, 2026 announcement, Cloudflare raised the limit for Workers Paid plans from 3 to 10 requests per second (600 per minute), including the /screenshot quick-action endpoint. Cloudflare Browser Rendering limits announcement Only if your screenshot workflow calls Cloudflare Browser Rendering REST. Check that the plan and interface you use are covered.
Zone WAF rate-limiting rule Incoming requests to a host and route in your zone; you choose what matches, how requests share a counter, and what happens at the threshold. Cloudflare rate limiting rules Yes. Use this to limit callers of your own screenshot endpoint.

The global API figure is not a sensible default for a screenshot endpoint. Pick an application threshold based on observed legitimate demand, burst patterns, and how much abuse or false blocking you can tolerate.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the rule’s scope and caller identity

Use a zone-level rule for a route in one zone

Cloudflare’s zone-level Rulesets API workflow uses the http_ratelimit phase entry-point ruleset. Retrieve the existing entry-point ruleset first. If it exists, use its ID when adding the rule; if it does not, create the entry-point ruleset with the rule included. Rate-limit rules belong at the end of the rules list. See the zone-level API procedure.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Decide who shares a counter

A rule’s characteristics determine which requests are counted together. Cloudflare’s parameters reference describes cf.colo.id as mandatory and documents supported characteristics such as source IP and request-header values. A source-IP counter is straightforward, but users behind a shared office, carrier, or proxy address can affect one another. A caller key can separate customers, but requests without that header require deliberate handling; do not assume a missing value identifies a unique caller. Cloudflare rate-limit parameters

Match only the screenshot route, preferably on the intended hostname as well. Add a method condition if it is available for your plan and useful to distinguish operations. Expression fields and some behaviors vary by plan, so verify them in the target account before deployment. A broad path such as /api/ may unintentionally throttle unrelated endpoints.

Build a rule body and deploy it

This illustrative rule limits one path and uses source IP as the caller characteristic in addition to the required Cloudflare data-center characteristic. Its threshold and timeout are examples for demonstrating the API shape only—not recommendations. Replace the hostname, path, identity, and values to fit your service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
{
  "description": "Rate limit screenshot requests",
  "expression": "(http.host eq "shots.example.com" and http.request.uri.path eq "/api/screenshot")",
  "action": "block",
  "ratelimit": {
    "characteristics": ["cf.colo.id", "ip.src"],
    "period": 60,
    "requests_per_period": 100,
    "mitigation_timeout": 600
  }
}

In this example, period is the evaluation interval in seconds, requests_per_period is the threshold, and mitigation_timeout is how long mitigation applies after triggering. The sample values resemble Cloudflare’s published syntax example, not a calibrated screenshot-service policy. Cloudflare’s example also shows matching an API-key header as a characteristic; use a caller-specific characteristic only if clients reliably send it and you have considered requests where it is absent.

Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
  1. Create or identify a Cloudflare API token with the permissions needed for the zone Rulesets API operation. Cloudflare’s Browser Rendering REST documentation separately specifies the Browser Rendering – Edit permission for Browser Rendering calls; that is not a substitute for Rulesets permissions. Scope credentials to only the required resources and operations.
  2. Retrieve the zone’s http_ratelimit phase entry-point ruleset using the endpoint and request format in Cloudflare’s API instructions.
  3. If the entry-point ruleset exists, add the rate-limit rule using its ID and preserve the existing rules. If it does not exist, create the phase entry-point ruleset with the rule included.
  4. Place the new rate-limit rule at the end of the rules list, then submit the API request and check Cloudflare’s response for success and the resulting ruleset.
  5. Test from representative clients and inspect rule events and application behavior. Adjust the expression, caller characteristic, period, threshold, and mitigation based on legitimate bursts as well as abuse cases.

Cloudflare’s API examples use bearer-token authentication. Use the exact zone and ruleset endpoints, method, and request envelope specified in its current API procedure; these depend on whether you are creating or updating the ruleset.

Set the counter, threshold, and mitigation deliberately

  • Match expression: constrain the rule to the screenshot host and path. Add method or other fields only when supported for your plan and necessary to the policy.
  • Characteristics: choose whether one source IP, a caller key, or another supported identity shares the counter. Evaluate fairness for shared IP addresses and the behavior of missing headers.
  • Period and threshold: choose the interval and number of requests from measured normal traffic and burst behavior. A frequent short burst may warrant a different policy from a sustained high rate.
  • Action and timeout: select an available action such as block or challenge where suitable; set mitigation duration to match the desired recovery window. A custom response can accompany a block action.
  • Counting expression: by default, the counting expression follows the rule expression. A custom counting expression can refine which matched traffic increments the counter.
  • Cache and origin: the requests_to_origin parameter controls whether only requests reaching origin are counted in applicable configurations. Support and restrictions vary; confirm whether cached screenshot responses should count for your use case. Cloudflare parameter details

When account-level rules are appropriate

An account-level ruleset can apply a shared policy across eligible zones rather than creating separate zone rules. Cloudflare’s documented API procedure creates a custom ruleset in the http_ratelimit phase and deploys it through the account phase entry-point ruleset with an execute rule. The documented account-level rate-limiting ruleset procedure is restricted to Enterprise zones and its example includes cf.zone.plan eq "ENT". Check current plan eligibility and token permissions—Cloudflare lists Account WAF Write or Account Rulesets Write for the illustrated workflow—before implementing it. Cloudflare account-level rate-limiting procedure

What enforcement can and cannot guarantee

A WAF rate limit is a mitigation control, not a precise request gate. Cloudflare states: “Rate limiting rules are not designed to allow a precise number of requests to reach your origin server.” Counters may take a few seconds to update, so additional requests can reach origin before mitigation takes effect. Some Enterprise customers may have throttling above the configured maximum, depending on plan or add-on; do not assume it is available on every account. Cloudflare rate limiting rules

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If your application must enforce a strict per-customer quota, use application-side accounting or another authoritative quota mechanism in addition to the WAF rule. The WAF can reduce bursts and blunt abuse, but its delayed counter updates mean it should not be treated as an exact billing meter.

Rank #3
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common problems

The rule is rejected by the API

Check the phase entry-point ruleset ID, zone scope, JSON syntax, token permissions, and the expression fields supported by the plan. Ensure the rule is included in or appended to the correct http_ratelimit ruleset and is placed last, as Cloudflare requires.

Legitimate users block one another

This commonly indicates that the counter identity is too broad, such as a shared source IP. Consider a supported caller-specific header characteristic, and verify that clients consistently send it. Account for absent header values rather than treating them as distinct by assumption.

Requests do not count as expected

Review the match expression and counting expression, then determine whether cached responses or only origin-bound requests should increment the counter. Check whether the configuration uses requests_to_origin and whether that setting is supported for the account and rule.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More requests reach the origin than the configured threshold

A few seconds of counter lag can allow over-threshold traffic through before mitigation applies. Lowering the threshold may reduce exposure but can increase false positives; load-test and monitor with representative bursts rather than assuming an exact cutoff.

Rank #4
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

Your screenshot calls are throttled even though the WAF rule is not involved

Identify whether the failing request is going to Cloudflare’s own client API or Browser Rendering REST API. Their service quotas are separate from the WAF rule on your zone. Cloudflare’s API responses can include Ratelimit and Ratelimit-Policy headers, and retry-after after a limit is exceeded; its SDKs automatically use these headers and back off. See API limits and response behavior.

Or skip the browser setup

If you want screenshots without building and maintaining a browser workflow, ScreenshotNeo is a screenshot API and MCP server for developers. One GET request returns a PNG, JPEG, WebP, or PDF. For details, see the ScreenshotNeo API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each cleanup step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, and responses identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The free plan includes 1,000 screenshots a month without a card; paid plans start at $5 for 3,000 shots. Sign up free for 1,000 screenshots a month, with no card required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can a Cloudflare rate-limit rule enforce an exact per-customer screenshot quota?

No. Cloudflare warns that rate-limit counters can lag and are not designed to permit a precise number of origin requests. Use application-side quota accounting for strict limits.

Does the 10-requests-per-second Browser Rendering limit apply to every Cloudflare screenshot setup?

No. Cloudflare announced it for Browser Rendering REST API on Workers Paid plans; confirm that your plan and REST interface are covered.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.