Skip to main content

Overview

VIZOCHOK enforces rate limits at three tiers to protect the platform, ensure fair usage, and prevent abuse:

Tier 1: Per-Connection

10 messages / 60 seconds (sliding window per WebSocket)

Tier 2: Per-User

200 messages / day, 20 conversations / day (per user)

Tier 3: Per-Tenant

500,000 tokens / day, 10,000,000 tokens / month (per tenant)
Each tier is checked in order. If any tier rejects the request, an error is returned immediately and subsequent tiers are not checked.

Tier 1: Per-Connection Rate Limit

Protects against rapid message flooding on a single WebSocket connection.

How It Works

The server tracks message frequency per connection and rejects messages that exceed the limit.

Error Response

The retry_after field indicates how many seconds until the oldest message in the window expires and a new message can be sent.

Connection Limit

Each API key is also limited to a maximum of 3 concurrent WebSocket connections. Exceeding this limit closes the new connection with close code 4029.

Tier 2: Per-User Rate Limit

Prevents individual users from consuming excessive resources.

How It Works

Counters reset daily at midnight UTC. Rate limits are tracked per authenticated user. Always pass userId in the widget config for accurate per-user tracking.

Error Responses

Configuring Limits

Per-user limits are configurable per tenant via the Admin Panel.

Tier 3: Per-Tenant Rate Limit

Prevents a single tenant from consuming disproportionate LLM resources.

How It Works

Token usage is recorded after each AI response and checked before processing new messages. Both daily and monthly limits are enforced.

Error Responses

Tenant token limits affect all users of a tenant. When a tenant hits the daily or monthly limit, no user under that tenant can send new messages until the limit resets.

Usage Alerts

VIZOCHOK sends a one-time alert notification when a tenant reaches 80% of their monthly token budget.

Configuring Limits

Per-tenant token limits are configurable via the Admin Panel.

Additional Limits

Beyond the three tiers, the system enforces several other limits:

What Happens When Limits Are Hit

Best Practices for High-Traffic Stores

1. Set Appropriate Per-User Limits

For high-traffic stores, consider lowering per-user limits to prevent individual users from consuming a disproportionate share of the tenant’s token budget:
  • Messages per day: 50-100 for most retail use cases
  • Conversations per day: 5-10

2. Monitor Token Usage

Use the admin panel dashboard to monitor daily and monthly token consumption. VIZOCHOK automatically sends an alert when you reach 80% of your monthly budget.

3. Optimize with Smart Prompts

Configure your tenant’s system prompt to encourage concise interactions:
  • Provide clear store rules to reduce unnecessary tool calls
  • Disable tools that are not relevant to your use case via disabled_tools

4. Use User IDs for Accurate Tracking

Always pass userId in the widget config when the user is authenticated. This enables accurate per-user rate limiting rather than falling back to per-API-key limits.

5. Handle Limit Errors Gracefully

Listen for limit errors in the onError callback and provide appropriate feedback:

Monitoring Usage

Monitor your current usage in the Admin Panel dashboard, which shows:
  • Tenant’s token count for today and this month
  • Per-user message and conversation counts
  • Usage trends and alerts
Usage data is also available via the REST API — see the API Reference tab.