Tutorials System Design Tutorial
Rate Limiting Strategies — Complete Guide
Rate Limiting Strategies — Complete Guide: free step-by-step lesson with examples, common mistakes, and interview tips — part of System Design Tutorial on Toolliyo Academy.
On this page
System Design Tutorial · Lesson 16 of 100
Rate Limiting Strategies
Basics → Scale → Interview
Basics · 1 — Building blocks · ~6 min · Module 2: Networking and Traffic Management
What is this?
Rate limiting caps how many requests a client can make per window — protecting APIs from abuse and noisy neighbors.
Why should you care?
One buggy ShopNest script can exhaust checkout capacity for everyone.
See it live — copy this example
Sketch the architecture on paper. These lessons focus on concepts and trade-offs.
Strategies:
fixed window: 100 req / minute / user
token bucket: burst 20 then steady 5 rps
sliding window: smoother than fixed
Keys: userId | IP | API key
ShopNest: stricter on /pay than on /search
Run Example »
This lesson uses terminal or setup steps. Run commands on your computer — the live editor appears on coding lessons.
What happened?
- Token buckets allow short bursts.
- Fixed windows are simple but can spike at boundaries.
- Put stricter limits on expensive or sensitive routes.
Practice next
- Pick limits for search vs pay.
- Choose userId as the primary key when logged in.
- Return 429 with Retry-After.
- Add a burst-friendly bucket for search autocomplete.
- Ban keys that exceed 10× limit.
Remember
Limits protect shared capacity. Match algorithm to traffic shape. Sensitive routes get tighter caps.
Checkout rate caps
ShopNest gateway limits /pay to 5 rps per user.
Outcome: Card-testing bots get 429; real users still check out.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!