RATE LIMITING

1

Overview

What Rate Limiting Is

Rate Limiting controls how many requests a client can make within a period of time. It protects your applications against abuse, brute-force attacks, excessive scraping, and ensures fair availability for every user.

The Buffet Analogy

Imagine an all-you-can-eat buffet with a rule: a maximum of 3 trips to the counter per hour. Anyone who tries 10 times gets stopped. Rate Limiting works the same way: it defines a request limit per period, and whoever exceeds it gets blocked or challenged.

Features

  • Protection against API abuse
  • Defense against brute force
  • Scraping control
  • Guaranteed availability
  • Controlled infrastructure costs
1/9
TRAFFIC SOURCESCLIENTE NORMAL👤5 req/min✓ Under limitCLIENTE PESADO⚡95 req/min⚠ Near limitCLIENTE ABUSIVO💀500 req/min🚫 Over limitRate exceeded 5xRATE LIMITINGCOUNTING EXPRESSIONO que contar?cf.client.ipContar por IPuri.pathPor endpointheadersPor API keyREQUEST COUNTER5/10095/100500/100Requests / minTHRESHOLD CHECKLimite: 100 req/minCounter ≤ Threshold?MITIGATION ACTIONS🚫 Block (429)🤖 Challenge📝 Log Only📄 CustomRATE LIMITING ANALYTICS📊 Requests Blocked📈 Top IPs🔔 Alert Rules📍 330+ PoPs globally⚡ <50ms detectionFlexible counting • Custom thresholds • Real-time enforcementALLOWED✓→ Origin ServerHTTP 200 OKCHALLENGE🤖JS / CAPTCHAProve you're humanBLOCKED🚫Rate LimitedHTTP 429 Too ManyLEGENDAUnder LimitNear LimitOver LimitAnalytics