Skip to content

Topic

Rate limiting

A control that caps how many requests a client, tenant, or IP can make in a given time window, protecting services from overload or abuse.

Current stories

build1 publisher

Every request that clears the edge still costs a PHP worker

A dev.to layering guide for self-hosted Laravel admins runs from ufw defaults through ModSecurity to a five-per-minute login limiter. Both fail2ban and that limiter depend on resolving the real client IP.

Publishers:dev.to

Reality

Evidence36
Adoption
Insufficient
Hype gap+12
Incentives62
Confidence54
build1 publisher

Bijira's reset header pinned its rate limit to the clock minute

Setting 5 requests per 60 seconds in Bijira's console took a form field and a dropdown. Working out what the gateway meant by 60 seconds took two corrected conclusions and a header that read 57 where a rolling window would have read 60.

Publishers:dev.to

Reality

Evidence66
Adoption10
Hype gap−12
Incentives32
Confidence55
build1 publisher

Scry's congestion pricing turns an agent's retry into a purchase

Scry's MCP search API prices an over-quota query instead of refusing it. That moves congestion control into the agent's retry loop, where a backoff timer cannot see the quote and the budget arbiter is the orchestrator's problem.

Publishers:dev.to

Reality

Evidence22
Adoption
Insufficient
Hype gap+45
Incentives
Insufficient
Confidence30

Earlier coverage

  1. Per-tenant Claude clients belong in the dependency graph, not in middleware

    Build · August 14, 2026 · 1 publisher