DFIELDSOLUTIONS

Security

GlossaryRate limiting

A control that caps how many requests a client can make in a time window — the basic defence against brute force, scraping, abuse and runaway API costs.

Without a limit, every endpoint is an invitation: login forms invite credential stuffing, search endpoints invite scraping, and paid APIs invite bills. A rate limiter counts requests per key — IP, account, token — and answers the excess with a 429 instead of the resource. Sensible limits differ per endpoint: expensive or sensitive routes get strict budgets, static reads get loose ones.

The common implementations are token bucket and sliding window counters in a shared store like Redis, so the limit survives horizontal scaling. The subtler part is the response: a Retry-After header and a predictable 429 let well-behaved clients back off gracefully, while silent drops just generate retries.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain