freecoding.school100% FREE · NO SIGNUP
Gateway RidgeISSUE #1 of 35

rate limiting · protecting the api

Gateway GusVSTimeout Titan
Gateway Gus saysRate limiting caps how many requests a client can make — protecting the API from overload and abuse.

To stay healthy and fair, APIs limit request rates per client/key (e.g. 100/minute). Exceed it and you get 429 Too Many Requests, often with a Retry-After header and X-RateLimit-* headers telling you your remaining quota. Limits protect against abuse, runaway clients, and cost blowouts. Clients should respect the headers and back off.

Power-ups you unlock

Timeout Titan attacks — common mistakes

Boss battleDescribe how a well-behaved client reacts to a 429 with Retry-After.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>429 Too Many Requests
Retry-After: 30
X-RateLimit-Remaining: 0
→ wait 30s, then retry</pre></body></html>
▶ Open the interactive comic issue
Rate Limiting · Token Bucket · Sliding Window ›