Api Rate Limiting

by secondsky88378361314fMIT227 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 10 days ago

Implements API rate limiting using token bucket, sliding window, and Redis-based algorithms to protect against abuse. Use when securing public APIs, implementing tiered access, or preventing denial-of-service attacks.

AI-generated overview

Guides implementing API rate limiting with token bucket, sliding window, and Redis-based strategies.

What it does
This skill provides reference guidance for adding rate limiting to APIs, covering token bucket, sliding window, and fixed window algorithms with their trade-offs. It includes example Node.js token bucket code, Express middleware configuration, standard rate limit response headers, and tiered request limits. It also lists best practices such as using Redis for distributed limiting and returning 429 responses with Retry-After.
When to use it
Use it when protecting public APIs from abuse, implementing tiered access by plan, or preventing denial-of-service attacks. It is suited to developers adding request throttling to an existing API.
Requirements
No scripts are shipped; it is instructions only. Applying the examples requires a Node.js environment, optionally the express-rate-limit package, and Redis for distributed rate limiting.

API Rate Limiting

Protect APIs from abuse using rate limiting algorithms with per-user and per-endpoint strategies.

Algorithms

AlgorithmProsCons
Token BucketHandles bursts, smoothMemory per user
Sliding WindowAccurateMemory intensive
Fixed WindowSimpleBoundary spikes

Token Bucket (Node.js)

javascript
class TokenBucket {  constructor(capacity, refillRate) {    this.capacity = capacity;    this.tokens = capacity;    this.refillRate = refillRate; // tokens per second    this.lastRefill = Date.now();  }
  consume() {    this.refill();    if (this.tokens >= 1) {      this.tokens--;      return true;    }    return false;  }
  refill() {    const now = Date.now();    const elapsed = (now - this.lastRefill) / 1000;    this.tokens = Math.min(this.capacity, this.tokens + elapsed * this.refillRate);    this.lastRefill = now;  }}

Express Middleware

javascript
const rateLimit = require('express-rate-limit');
const limiter = rateLimit({  windowMs: 15 * 60 * 1000, // 15 minutes  max: 100,  standardHeaders: true,  message: { error: 'Too many requests, try again later' }});
app.use('/api/', limiter);

Response Headers

X-RateLimit-Limit: 100X-RateLimit-Remaining: 45X-RateLimit-Reset: 1705320000Retry-After: 60

Tiered Limits

TierRequests/Hour
Free100
Pro1,000
Enterprise10,000

Best Practices

  • Use Redis for distributed rate limiting
  • Include proper headers in responses
  • Return 429 status with Retry-After
  • Implement tiered limits for different plans
  • Monitor rate limit metrics
  • Test under load

Source and attribution

Source:secondsky/claude-skillsinplugins/api-rate-limiting/skills/api-rate-limitingat commit8837836

License: MIT

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal