Web Development
Application Development
UI/UX Design
DevOps Consulting
Cloud Services
Blockchain Development
QA & Testing
Support & Maintenance
Ecommerce
Fintech
Real Estate
Healthcare
Logistics
Education
Fitness
Travels & Hospitality
73, Swashray Soc, Diwali Baug, Athwa Gate, Surat- 395001,
Guj- Bharat.
Back to Articles
BotNET IT Team
September 28, 2025
5 min read
Abuse was hammering our client's API—thousands of requests per minute from a handful of IPs. We added rate limiting: 100 requests per minute per IP. Problem solved. New problem created.
A corporate client with 200 employees behind a single NAT gateway hit the limit by 10 AM every day. Legitimate users got 429 errors. Support tickets flooded in.
We switched from IP-based to token-based rate limiting for authenticated requests. Anonymous/public endpoints kept IP limits but with a higher threshold. We also added a sliding window instead of a hard reset every minute.
Rate limiting protects your API. Just make sure you're limiting the right thing.
Tags: