# Rate limiting

> A control that caps how many requests a client can make in a time window — the basic defence against brute force, scraping, abuse and runaway API costs.

Without a limit, every endpoint is an invitation: login forms invite credential stuffing, search endpoints invite scraping, and paid APIs invite bills. A rate limiter counts requests per key — IP, account, token — and answers the excess with a 429 instead of the resource. Sensible limits differ per endpoint: expensive or sensitive routes get strict budgets, static reads get loose ones.

The common implementations are token bucket and sliding window counters in a shared store like Redis, so the limit survives horizontal scaling. The subtler part is the response: a Retry-After header and a predictable 429 let well-behaved clients back off gracefully, while silent drops just generate retries.

## Related terms

- https://dfieldsolutions.com/en/glossary/owasp-top-10.md
- https://dfieldsolutions.com/en/glossary/incident-response.md
- https://dfieldsolutions.com/en/glossary/threat-model.md

---

Source: https://dfieldsolutions.com/en/glossary/rate-limiting
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
