.Net Tips – Using custom ServiceThrottlingAttribute to specify WCF service throttling behaviour

You can become a serverless blackbelt. Enrol to my 4-week online workshop Production-Ready Serverless and gain hands-on experience building something from scratch using serverless technologies. At the end of the workshop, you should have a broader view of the challenges you will face as your serverless architecture matures and expands. You should also have a firm grasp on when serverless is a good fit for your system as well as common pitfalls you need to avoid. Sign up now and get 15% discount with the code yanprs15!

If you have created a WCF service in the past then I assume you’re aware that WCF is very heavily configuration-driven and that you can specify the service behaviour including the throttling parameters (MaxConcurrentCalls, MaxConcurrentInstances, MaxConcurrentSessions) in the config file.
But to specify the type of service (PerCall, PerSession or Singleton) you need to apply the ServiceBehaviour attribute to your type.
Now, wouldn’t it be nice if you can specify the service throttling behaviour as an attribute as well rather than having to rely on config files?
I can see the reasoning behind putting these in the config file so you don’t have to recompile and redistribute whenever you wishes to change the throttling behaviour, but there are certain edge cases where it warrants the use of such attribute. For instance, my WCF services are dependency injected through a custom wrapper and I want different throttling behaviour for each service rather than a carpet throttling behaviour which applies to all my services.


Whilst there’s no built-in ServiceThrottlingAttribute in the framework, you can easily write one yourself. Here’s one I wrote the other day based on Ralph Squillace’s code sample here:
I made some modification so you don’t HAVE TO specify the value for each type of throttling and will use the default values where possible.
[AttributeUsage(AttributeTargets.Class, AllowMultiple = false)]
public sealed class ServiceThrottlingAttribute : Attribute, IServiceBehavior
    public int MaxConcurrentCalls { get; set; }
    public int MaxConcurrentInstances { get; set; }
    public int MaxConcurrentSessions { get; set; }
    public void Validate(ServiceDescription serviceDescription, ServiceHostBase serviceHostBase)
    public void AddBindingParameters(ServiceDescription serviceDescription, ServiceHostBase serviceHostBase, Collection<ServiceEndpoint> endpoints, BindingParameterCollection bindingParameters)
    public void ApplyDispatchBehavior(ServiceDescription serviceDescription, ServiceHostBase serviceHostBase)
        var currentThrottle = serviceDescription.Behaviors.Find<ServiceThrottlingBehavior>();
        if (currentThrottle == null)

    private ServiceThrottlingBehavior GetConfiguredServiceThrottlingBehaviour()
        var behaviour = new ServiceThrottlingBehavior();
        if (MaxConcurrentCalls > 0)
            behaviour.MaxConcurrentCalls = MaxConcurrentCalls;
        if (MaxConcurrentInstances > 0)
            behaviour.MaxConcurrentInstances = MaxConcurrentInstances;
        if (MaxConcurrentSessions > 0)
            behaviour.MaxConcurrentSessions = MaxConcurrentSessions;

        return behaviour;


Before you go ahead and create yourself an ultra-scalable service by setting the max concurrent calls/sessions/instances values to be very high you need to be aware what the performance implications are.

First, you need to know that WCF is configured to be safe from DOS attacks out of the box and the default configurations for service throttling behaviour is very conservative:

  1. MaxConcurrentCalls – default is 16, represents the max number of messages that can actively be processed.
  2. MaxConcurrentInstances – default is 26. For a “PerSession” service this represents the max number of session; for a “PerCall” service this represents the max number of concurrent calls; for a “Singleton” service this is meaningless.
  3. MaxConcurrentSessions – default is 10, represents the max number of sessions a service can accept at one time and only affects session-enabled channels. Increase this to allow more than 10 concurrent sessions.
Prevention of DOS attacks aside, each concurrent request your service is processing also requires at least a new thread to carry out the task. Whilst I don’t know whether WCF uses the framework ThreadPool (which also has further performance implications, see here), there is a balance between the number of concurrent threads and how much time the CPU spends on context switching between the different threads. Too many concurrent threads and the performance starts to suffer as well as the response times, too few concurrent threads and the CPU is under utilised, the response times suffer and more requests are timed out as they wait in the queue.
According to Dan Rigsby’s blog post on throttling WCF services (see references section below), the recommendations for each type of service is as follows:


If your InstanceContext is set to “PerCall” you should set maxConcurrentSessions and maxConcurrentCalls to the same value since each call is its own session.  You should target this value to be at least 25-30.  However you shouldn’t need to go higher than 64.

If your InstanceContext is set to “PerSession” you should set maxConcurrentCalls to be at least 25-30.  Your maxConcurrentSessions should be the number of users you want to have concurrently connected.

If your InstanceContext is set to “Single” you should use the same settings as “PerSession”, but the maxConcurrentSessions will only apply if session support is active (this is set with the SessionMode attribute on the ServiceContractAttribute).


Dan Rigsby’s blog post on thorttling WCF services

Liked this article? Support me on Patreon and get direct help from me via a private Slack channel or 1-2-1 mentoring.
Subscribe to my newsletter

Hi, I’m Yan. I’m an AWS Serverless Hero and I help companies go faster for less by adopting serverless technologies successfully.

Are you struggling with serverless or need guidance on best practices? Do you want someone to review your architecture and help you avoid costly mistakes down the line? Whatever the case, I’m here to help.

Hire me.

Skill up your serverless game with this hands-on workshop.

My 4-week Production-Ready Serverless online workshop is back!

This course takes you through building a production-ready serverless web application from testing, deployment, security, all the way through to observability. The motivation for this course is to give you hands-on experience building something with serverless technologies while giving you a broader view of the challenges you will face as the architecture matures and expands.

We will start at the basics and give you a firm introduction to Lambda and all the relevant concepts and service features (including the latest announcements in 2020). And then gradually ramping up and cover a wide array of topics such as API security, testing strategies, CI/CD, secret management, and operational best practices for monitoring and troubleshooting.

If you enrol now you can also get 15% OFF with the promo code “yanprs15”.

Enrol now and SAVE 15%.

Check out my new podcast Real-World Serverless where I talk with engineers who are building amazing things with serverless technologies and discuss the real-world use cases and challenges they face. If you’re interested in what people are actually doing with serverless and what it’s really like to be working with serverless day-to-day, then this is the podcast for you.

Check out my new course, Learn you some Lambda best practice for great good! In this course, you will learn best practices for working with AWS Lambda in terms of performance, cost, security, scalability, resilience and observability. We will also cover latest features from re:Invent 2019 such as Provisioned Concurrency and Lambda Destinations. Enrol now and start learning!

Check out my video course, Complete Guide to AWS Step Functions. In this course, we’ll cover everything you need to know to use AWS Step Functions service effectively. There is something for everyone from beginners to more advanced users looking for design patterns and best practices. Enrol now and start learning!