- All Courses
- API Design with Node.js
- Auth and Safety
- Rate limiting and abuse prevention
Lesson 3.3
Rate limiting and abuse prevention
Rate limits protect availability and cost.
18mBeginner12.5k students
Overview
Fair use, enforced
Rate limits protect availability and cost. Limiting per authenticated identity is far more accurate than per ip address, since many legitimate users share addresses and one attacker can use many.
Communicate the limit. Returning the remaining quota and a retry-after header lets well-behaved clients back off correctly instead of hammering you into a longer ban.
Expensive endpoints deserve their own limits. Search, export, and anything invoking a model cost far more per call than a simple read, and a global limit prices them identically.
In this lesson you will:
- Limit per identity, not just per address
- Tell clients their limit and reset time
- Protect expensive endpoints specifically
Resources
Notes are not saved yet — they clear when you leave this page.
Previous Lesson
Authorisation and scopes
8m
Documenting with OpenAPI
5m