Lesson 3.3

Rate limiting and abuse prevention

Rate limits protect availability and cost.

18mBeginner12.5k students

Overview

Fair use, enforced

Rate limits protect availability and cost. Limiting per authenticated identity is far more accurate than per ip address, since many legitimate users share addresses and one attacker can use many.

Communicate the limit. Returning the remaining quota and a retry-after header lets well-behaved clients back off correctly instead of hammering you into a longer ban.

Expensive endpoints deserve their own limits. Search, export, and anything invoking a model cost far more per call than a simple read, and a global limit prices them identically.

In this lesson you will:

  • Limit per identity, not just per address
  • Tell clients their limit and reset time
  • Protect expensive endpoints specifically

Resources

Previous Lesson
Next Lesson
Rate limiting and abuse prevention — API Design with Node.js — Vertex