Rate Limiting
Algorithms, shared counters, and signalling rejection properly.
4 to work through
-
advanced
A payments API must stay available on the highest-traffic commerce day of the year. How should rate limiting and load shedding be structured so that critical traffic survives while non-critical traffic is sacrificed?
2 min answer -
advanced
A rate limiter protects an API from abuse, but enterprise customers have legitimate predictable bursts. How should quotas differ by tenant, endpoint, priority and available capacity?
2 min answer -
advanced
An AI platform serves customers from individual developers to large enterprises, where a single request can be a thousand times more expensive than another. How should rate limiting be designed?
2 min answer -
advanced
Design rate limiting for a multi-tenant API where a single customer's traffic spike currently degrades service for everyone.
2 min answer
4 terms in this topic
Rate Limit Design
The algorithm, scope and response behaviour that determine whether throttling protects the service and treats callers fairly.
patternRate Limiting in Practice
Bounding how much work one caller can demand, the algorithm choice that shows through to users, and why distributed enforcement is approximate.
protocolRetry-After
A response header telling a client how long to wait before retrying, turning a rejection into actionable guidance.
patternToken Bucket
A rate-limiting algorithm holding a replenishing allowance of tokens, permitting controlled bursts while bounding the sustained rate.
Neighbouring topics
API & Integration
General material on integrating systems through contracts.
REST Design
Resources, uniform methods, status codes and statelessness.
GraphQL
Client-specified queries, N+1 resolution and query-cost control.
gRPC APIs
Contract-first RPC, generated clients and protobuf compatibility rules.
Webhooks
Push callbacks, signature verification, ordering and at-least-once delivery.
API Versioning
URL, header and account-pinned versioning, and who carries the burden.
Backward Compatibility
Which changes are safe, and how to make breakage a build failure.
Contract Testing
Verifying what consumers actually rely on, without a shared environment.
API Documentation
OpenAPI as a machine-checked contract rather than as prose.
Idempotency Keys
Client-generated keys stored atomically with the operation they guard.
Pagination & Filtering
Offset versus cursor, stable ordering and unbounded result sets.
API Error Handling
Error shapes, retryability signals and machine-readable causes.
Event-Driven Integration
Publishing facts rather than commands, and versioning event schemas.
Message Formats
JSON, Protobuf, Avro — schema evolution and payload economics.
Schema Registry
Enforcing compatibility on events the way CI enforces it on code.
Integration Patterns
Routers, translators, splitters, aggregators and dead letter channels.
Legacy Integration
Reaching systems that cannot change, without importing their model.
Partner & B2B Integration
External contracts, onboarding, sandboxes and long deprecation windows.
APIs as Products
Ownership, lifecycle, deprecation policy and developer experience.