Without a limit, every endpoint is an invitation: login forms invite credential stuffing, search endpoints invite scraping, and paid APIs invite bills. A rate limiter counts requests per key — IP, account, token — and answers the excess with a 429 instead of the resource. Sensible limits differ per endpoint: expensive or sensitive routes get strict budgets, static reads get loose ones.
The common implementations are token bucket and sliding window counters in a shared store like Redis, so the limit survives horizontal scaling. The subtler part is the response: a Retry-After header and a predictable 429 let well-behaved clients back off gracefully, while silent drops just generate retries.
Related terms
OWASP Top 10
The long-standing community list of the most critical web application security risks, revised every few years.
Incident response
The plan and the practice for what happens between noticing something is wrong and being back to normal.
Threat model
A written answer to who would attack this, what they would want, and what would actually stop them.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
