qodebase logoqodebase
← All tracks

Unit 4 — fixed window, sliding window, and token buckets at scale

Rate Limiting

A single buggy integration can hammer your API with 50,000 requests a second, starving every other merchant. A credential-stuffing script can probe login endpoints relentlessly. The defense that keeps a shared platform fair and alive is the rate limiter: a sub-millisecond decision, made on every request, about whether to serve it or shed it.

This unit builds the three rate limiters every backend engineer should know — fixed window, sliding window, and token bucket — shows where the cheap one breaks, and benchmarks the trade-off between accuracy and memory.

Rate Limiting — qodebase — qodebase