Cloudflare Rate Limiting for cookie, or authentication token

Hi everyone,
I read this article and saw that Cloudflare Rate Limiting supports to limit requests per second per IP, cookie, or authentication token. But I only see options request per IP in the dashboard. How can I set a rate-limit rule for requests per cookie or authentication token?
I’m also confused about rate-limit by IP. If users in the same network (company or university) call API, the counter bases on an individual user or all users with the same IP?
Thank you.

