Guides implementing API rate limiting with token bucket, sliding window, and Redis-based strategies.
- What it does
- This skill provides reference guidance for adding rate limiting to APIs, covering token bucket, sliding window, and fixed window algorithms with their trade-offs. It includes example Node.js token bucket code, Express middleware configuration, standard rate limit response headers, and tiered request limits. It also lists best practices such as using Redis for distributed limiting and returning 429 responses with Retry-After.
- When to use it
- Use it when protecting public APIs from abuse, implementing tiered access by plan, or preventing denial-of-service attacks. It is suited to developers adding request throttling to an existing API.
- Requirements
- No scripts are shipped; it is instructions only. Applying the examples requires a Node.js environment, optionally the express-rate-limit package, and Redis for distributed rate limiting.