Token bucket refills tokens at a steady rate and allows bursts up to the bucket size — the popular default. Leaky bucket drains at a constant rate (smooths bursts). Fixed window counts per clock interval (simple but spiky at boundaries); sliding window smooths that boundary problem. Each trades simplicity against burst behavior.
Power-ups you unlock
Token bucket: steady refill, allows bursts
Leaky bucket: constant drain, smooths bursts
Fixed window: simple, boundary spikes
Sliding window: smooths the boundary
Timeout Titan attacks — common mistakes
Fixed window letting double bursts at the edge
Bucket too small (blocks legit bursts)
Not communicating the limit to clients
Boss battleExplain why token bucket is favored for APIs that should tolerate short bursts.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>token bucket: +1 token / 600ms, cap 100
burst of 100 OK, then throttled to refill rate</pre></body></html>