Let's talk about your project

Rate limiting

A protection that limits how many requests a user, IP address or API key can make within a given period.

  1. 01

    Why it matters

    Rate limiting slows down password-guessing attacks, protects APIs against abuse and unexpected cost increases and helps keep the service available to everyone. Limits should be tuned to the function: a login page needs tighter limits than a search page. When the limit is exceeded, a clear response and a waiting time should be returned.

  2. 02

    Example

    In an application, at most five failed login attempts can be made on the same account within fifteen minutes. At this pace a password-guessing attack becomes ineffective in practice.

  3. 03

    Common mistake

    Setting limits only by IP address. Attackers can spread requests across thousands of addresses; limits per account and per action are needed too.

  4. 04
Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.