Do I need rate limiting?
Yes, on login, sign-up, password reset, anything that sends email or SMS, and every endpoint that calls a paid AI model. Without limits, anyone can guess passwords, create thousands of accounts, use you to send spam, or run up your AI bill in an afternoon. AI-built apps rarely include limits, because a demo never needs them.
Where to put limits
| Endpoint | Risk without a limit | Starting limit |
|---|---|---|
| Login | Password guessing | 5 to 10 attempts per account per 15 minutes |
| Sign-up | Fake account floods | A few per IP per hour, plus email confirmation |
| Password reset, magic links | Email bombing, cost | 3 per account per hour |
| AI endpoints | Your provider bill | Per-user daily token or request cap |
| Search and export | Scraping | Per-user per-minute cap |
How to add them
Use what your platform provides first: auth providers such as Supabase include some rate limits in their settings, hosting platforms and Cloudflare offer rules at the edge, and API gateways have built-in limits. For AI calls, count usage per user in your database and refuse beyond a cap. Set a hard spending limit at the model provider as a backstop.
The AI bill problem
An unauthenticated or unlimited endpoint that forwards to a paid model is the fastest way for an AI-built app to lose money. See stopping your AI bill being run up.
Signs you are being abused
Watch for spikes in sign-ups from similar email domains, many failed logins against one account or from one address, password reset emails sent faster than a person could request them, AI usage concentrated in a few new accounts, and email bounce rates rising because your app is sending to addresses nobody entered. Your email provider may suspend sending if abuse makes your bounce or complaint rates climb, which takes down legitimate emails such as password resets too.
Limits are cheaper than cleaning up after any of these. Add them before launch on the endpoints listed above, alert when they trigger often, and review the logs weekly for the first month.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Does a CAPTCHA replace rate limiting?
It helps on sign-up and login. It does not protect API endpoints called directly, so keep server-side limits too.
Will limits annoy real users?
Set them well above normal use. Real users rarely hit a sensible limit.