VibeCoded

Do I need rate limiting?

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Yes, on login, sign-up, password reset, anything that sends email or SMS, and every endpoint that calls a paid AI model. Without limits, anyone can guess passwords, create thousands of accounts, use you to send spam, or run up your AI bill in an afternoon. AI-built apps rarely include limits, because a demo never needs them.

Where to put limits

Suggested limits for a small app
EndpointRisk without a limitStarting limit
LoginPassword guessing5 to 10 attempts per account per 15 minutes
Sign-upFake account floodsA few per IP per hour, plus email confirmation
Password reset, magic linksEmail bombing, cost3 per account per hour
AI endpointsYour provider billPer-user daily token or request cap
Search and exportScrapingPer-user per-minute cap

How to add them

Use what your platform provides first: auth providers such as Supabase include some rate limits in their settings, hosting platforms and Cloudflare offer rules at the edge, and API gateways have built-in limits. For AI calls, count usage per user in your database and refuse beyond a cap. Set a hard spending limit at the model provider as a backstop.

The AI bill problem

An unauthenticated or unlimited endpoint that forwards to a paid model is the fastest way for an AI-built app to lose money. See stopping your AI bill being run up.

Signs you are being abused

Watch for spikes in sign-ups from similar email domains, many failed logins against one account or from one address, password reset emails sent faster than a person could request them, AI usage concentrated in a few new accounts, and email bounce rates rising because your app is sending to addresses nobody entered. Your email provider may suspend sending if abuse makes your bounce or complaint rates climb, which takes down legitimate emails such as password resets too.

Limits are cheaper than cleaning up after any of these. Add them before launch on the endpoints listed above, alert when they trigger often, and review the logs weekly for the first month.

Getting it checked

TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.

Get a scope for your app

Tell us what you built, what it stores and who is about to use it.

Get matched

Common questions

Does a CAPTCHA replace rate limiting?

It helps on sign-up and login. It does not protect API endpoints called directly, so keep server-side limits too.

Will limits annoy real users?

Set them well above normal use. Real users rarely hit a sensible limit.