/System Design /Rate Limiter ← All Designs
🛡️

Rate Limiter

Control request rates to protect services from overload and abuse

PHASE 3 SYSTEM DESIGN INTERACTIVE
Live Visualization
👤
CLIENT
0
requests sent
TOKEN BUCKET
Rate Limiter
14
tokens available
pass

reject
⚙️
SERVICE
0
processed
0
✓ Accepted
0
✗ Rejected 429
0%
Rejection Rate
0
Total Requests
0
Accepted
0
Rejected / 429s
0%
Rejection Rate %
📖 Algorithm Explanation
Key Concepts
🎯 When to Use
API gateways, login endpoints, payment APIs, any public-facing endpoint that needs protection from overload, DDoS, or abuse patterns.
⚖️ Trade-offs
Aggressive limits hurt legitimate users; too lenient lets abuse through. Need to decide per-user vs per-IP vs global limits based on use case.
💡 Interview Tip
"429 Too Many Requests with Retry-After header is the standard response. Always ask: per-user, per-IP, or global limit?"