AddThisFeature

Rate Limiting

Stop one client from ruining it for everyone.

moderate Security & Reliability

What it adds

Throttling on the endpoints that get abused: auth, search, exports, and public forms.

What your agent is told to do

4
  1. 1

    Identify the endpoints worth protecting: sign-in, sign-up, password reset, search, exports, and anything unauthenticated.

  2. 2

    Limit by a stable identifier — user ID where signed in, IP otherwise. Be aware IP is shared behind NAT and proxies.

  3. 3

    Return 429 with a Retry-After header. Do not silently drop the request.

  4. 4

    Be far stricter on authentication endpoints. Sign-in is where credential stuffing happens.

Edge cases it handles

5
  • Get the client IP correctly behind a proxy or CDN — a spoofable header is not a limit.
  • Do not rate-limit your own health checks, webhooks, or internal jobs into failure.
  • The limiter must fail OPEN or CLOSED deliberately — decide which, because it will fail.
  • Legitimate bursts (a user opening ten tabs) must not lock out a real customer.
  • Never leak whether an email exists via differential rate limiting on sign-in.

Definition of done

8
  • Auth, search, export, and public endpoints are limited.
  • 429 responses include Retry-After.
  • The client IP is derived correctly behind proxies.
  • Webhooks and health checks are exempt.
  • Failure behaviour is a deliberate decision.
  • Limits don't reveal whether an account exists.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.