Backend & AI

What is Rate limiting

What it is

A rule of "no more than N requests per period". It protects a site or bot from password guessing and spam, and an integration from being banned by someone else's service for calling it too often.

How we use it

After the move from Joomla, the WordPress login page accepts at most 20 requests a minute, the brief on the studio site at most three submissions per 10 minutes from one address, and the electronic queue one request per 0.5 seconds. ToshaMusic caps parallel downloads so the streaming account does not get banned.

Where it helps a business

  • Someone is guessing passwords on the admin login page.
  • Bots flood the website's request form with spam.
  • A user taps buttons quickly, and the bot processes one action several times.
  • Someone else's service bans your account for calling it too often.

How we use it

  • WordPress login. After the move from Joomla the entry nginx allows at most 20 requests a minute to the login page, and after three wrong passwords sign-in from that address closes for 15 minutes, then for an hour and a day on repeats.
  • Store login. In the online store five wrong passwords in a row lock sign-in for that username for 15 minutes, whatever the address.
  • A brief without a captcha. On the studio website: at most three submissions per 10 minutes from one address, plus a hidden trap field and rejection of submissions sent faster than four seconds.
  • Bot buttons. In the electronic queue: at most one request per 0.5 seconds per user.
  • Your account in someone else's service. ToshaMusic caps parallel downloads (two by default), the overall queue and tasks per user, so the streaming account does not get banned.

Common problems

  • A per-IP limit is not enough. Passwords are guessed from many addresses, so the store counts lockouts per username.
  • Counters in memory. The brief and queue counters live in process memory and reset on restart.

When you do not need it

A closed service available only to an allow-list of Telegram IDs is not at risk of password guessing. But limiting your own requests to other people's APIs is almost always needed.

← All terms

Need a website, a bot or automation?

Terms explained — now let's get to work: tell us about the task and we'll turn it into a clear work plan.