Rate Limiting Is an Act of Respect

D
Dick Edidiong Bassey
·

Without rate limiting, a single badly-behaved client can consume enough capacity to degrade performance for everyone. Rate limiting is resource fairness.

The correct implementation has multiple layers: per-IP rate limiting at the edge blocks volumetric attacks. Per-user authenticated rate limiting enforces fair-use policies. Per-endpoint rate limiting for authentication and payment initiation blocks credential stuffing.

For Afripay: authentication endpoints have a 5 requests per minute per IP limit. Payment initiation has 10 per minute per authenticated user.

Implement rate limiting with informative 429 responses including a Retry-After header.

— Dick Bassey | DevDick | 2023