Glossary Web & HTTP

Rate limiting

Rate limiting restricts how many requests a client can make to a service in a given time, to protect it from overload and abuse.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

Typical limits are "100 requests per minute per IP address" or per API key. When the limit is hit, the server replies with status 429 Too Many Requests and often a Retry-After header. Rate limits slow down password guessing and scraping and keep one noisy client from starving the others.

See also

  • Glossary Brute-force attack
    A brute-force attack tries every possible password or key, or a huge list of likely ones, until one works.
  • Glossary API
    An API (application programming interface) is a defined way for one piece of software to ask another to do something or share data.
  • Cheat sheet HTTP Status Codes Cheat Sheet
    The HTTP status codes you will actually meet, grouped by class, with the pairs people confuse (401 vs 403.
AdSense Placeholder
Slot: footer_leaderboard