Backend and APIs · Pattern

Rate limiting

Capping how many requests a user, key or IP address can make in a period of time, to stop abuse, brute-force attacks and runaway costs.

Jobs and glue · updated

How it works

A rate limiter counts requests per key (a user id, an API key, an IP address) in a time window and rejects the excess with HTTP 429 Too Many Requests, often with a Retry-After header. Common algorithms are fixed windows, sliding windows and the token bucket, which allows short bursts while holding the long-run average.

Counters usually live in a fast shared store such as Redis, so every server sees the same numbers; Upstash offers a ready-made library for serverless apps, and Cloudflare and API gateways can enforce limits before traffic reaches the app. Sign-in, OTP and password-reset endpoints, and anything that calls a paid AI model, need limits most.

More in Backend and APIs

Jobs and glue

All 26 Backend and APIs terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.