Rate limiting
A protection that limits how many requests a user, IP address or API key can make within a given period.
- 01
Why it matters
Rate limiting slows down password-guessing attacks, protects APIs against abuse and unexpected cost increases and helps keep the service available to everyone. Limits should be tuned to the function: a login page needs tighter limits than a search page. When the limit is exceeded, a clear response and a waiting time should be returned.
- 02
Example
In an application, at most five failed login attempts can be made on the same account within fifteen minutes. At this pace a password-guessing attack becomes ineffective in practice.
- 03
Common mistake
Setting limits only by IP address. Attackers can spread requests across thousands of addresses; limits per account and per action are needed too.
- 04
Let's talk about your project.
Tell us what you need; we will define the scope together.