Prerequisites and Permissions

Managing CCIP rate limits is a privileged, operator-level action. Before you inspect or modify any rate limit configuration, you must meet the prerequisites on this page.

Required permissions

To update rate limits, the submitting wallet must be either:

  • the pool owner, or
  • the address returned by getDynamicConfig() as rateLimitAdmin

The update function is setRateLimitConfig. Without one of these roles, you can read onchain data but cannot make changes.

In most cases, the rateLimitAdmin role is assigned to a multisig wallet rather than to an individual externally owned account.

How rate limit admin access is granted

Admin access is not self-assigned. Only the pool owner can set the rateLimitAdmin.

v2.0 pools

The rateLimitAdmin is set through setDynamicConfig:

function setDynamicConfig(
  address router,
  address rateLimitAdmin,
  address feeAdmin
) external;

Verify the current configuration:

function getDynamicConfig()
  external
  view
  returns (address router, address rateLimitAdmin, address feeAdmin);

The update function is setRateLimitConfig.

v1.x pools

v1.x pools use standalone admin functions:

function getRateLimitAdmin() external view returns (address);
function setRateLimitAdmin(address rateLimitAdmin) external; // owner only

The update functions are setChainRateLimiterConfig (single lane) or setChainRateLimiterConfigs (batch).

Scope of admin authority

rateLimitAdmin can:

  • update inbound and outbound rate limits for configured remote chains
  • on v2.0: update default and fast-finality buckets via setRateLimitConfig

rateLimitAdmin cannot:

  • add or remove remote chains (applyChainUpdates): owner only
  • change admin addresses: owner only (setDynamicConfig on v2.0; setRateLimitAdmin on v1.x)

Owner can:

  • everything rateLimitAdmin can do
  • add or remove remote chains via applyChainUpdates

Each token pool has its own owner and rateLimitAdmin. Their authority covers the inbound and outbound limits of every remote chain configured on that pool (and both bucket types on v2.0).

Operational expectations

Before you change anything, make sure that:

  • you understand the token's decimal precision and smallest unit on each chain you configure
  • you have reviewed the current inbound and outbound configurations (and fast-finality buckets on v2.0)
  • you are prepared to validate values carefully before submitting transactions
  • v2.0 pools: Config changes immediately refill buckets to full capacity.
  • v1.x pools: Config changes do not immediately refill to full capacity. The bucket continues refilling at the normal rate.

Rate limit changes are applied onchain and take effect immediately.

Responsibility boundary

By managing rate limits, you take responsibility for the availability of cross-chain transfers for the affected token and lane.

Incorrect configuration can:

  • unintentionally block transfers
  • allow more volume than intended
  • create operational or user-facing disruption

For this reason, rate limit management should follow a deliberate review process and use a multisig workflow where possible.

What's next

If you meet these prerequisites, the next step is to inspect the current inbound and outbound rate limit configuration before making any changes.

Get the latest Chainlink content straight to your inbox.