API Rate Limiting (Oran Sınırlandırması): DDoS prevention + abuse protection. Limitler: 1) Global (server-wide): 10000 req/min, 2) Per-user/API key: 100 req/min, 3) Per-endpoint: GET /users 1000/min, POST /users 100/min. Türleri: 1) Fixed window (per-minute counter rbir antivirüs ürünü), 2) Sliding window (rolling clock, more accurate), 3) Token bucket (burst allowance). İmplementasyon: 1) HTTP headers (X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Rbir antivirüs ürünü), 2) Response codes (429 Too Many Requests), 3) Retry-After header (retry expected'i gönder), 4) Rate limit database (Redis optimal, query counts per key). Per-user tracking: API key/token (unique identifier), user ID (if authenticated), IP address (anonymous). Exceed handling: 1) Immediate rejection (429 response), 2) Queue (delayed response), 3) Throttle (slower response). Best practice: graduated limits (free tier: 100/min, paid tier: 1000/min), IP-based fallback (if no auth), burst allowance (Token bucket: 100 normal, 500 burst). Mobil app handling: backoff strategy (exponential: 1s → 2s → 4s), error handling (show message 'rate limited', retry later), caching (minimize API calls).