API Rate Limiting: DDoS prevention + abuse protection. Limits: 1) Global (server-wide): 10000 req/min, 2) Per-user/API key: 100 req/min, 3) Per-endpoint: GET /users 1000/min, POST /users 100/min. Types: 1) Fixed window (per-minute counter reset), 2) Sliding window (rolling clock, more accurate), 3) Token bucket (burst allowance). Implementation: 1) HTTP headers (X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset), 2) Response codes (429 Too Many Requests), 3) Retry-After header (send expected retry time), 4) Rate limit database (Redis optimal, query counts per key). Per-user tracking: API key/token (unique identifier), user ID (if authenticated), IP address (anonymous). Exceed handling: 1) Immediate rejection (429 response), 2) Queue (delayed response), 3) Throttle (slower response). Best practice: graduated limits (free tier: 100/min, paid tier: 1000/min), IP-based fallback (if no auth), burst allowance (Token bucket: 100 normal, 500 burst). Mobile app handling: backoff strategy (exponential: 1s → 2s → 4s), error handling (show message 'rate limited', retry later), caching (minimize API calls).