The Developer Tools Podcast with Fexingo · 2026-07-24 · 10 min
A single aggressive user can degrade your entire API. In this episode, Lucas and Luna break down why per-endpoint rate limiting is a blunt instrument and why per-user rate limiting - paired with user-tier quotas - is the smarter pattern. Using the real-world example of a fintech API that saw 40% error-rate spikes during a bot attack, they walk through the design decisions: user-level token bucket vs. fixed-window per route, how to handle burst traffic from legitimate power users, and why returning a 429 with a 'reset-at' timestamp beats a generic 'rate limit exceeded' message. They also touch on the business case - protecting paid tiers from free-tier abuse without throttling your highest-value customers. If you're building an API that serves multiple clients with wildly different usage patterns, this episode gives you the concrete trade-offs you need. #RateLimiting #APIDesign #BackendEngineering #FairUsage #TokenBucket #FexingoBusiness #BusinessPodcast #DeveloperTools #APIInfrastructure #SoftwareEngineering #Fintech #BotMitigation #UserTiering #HTTP429 #Scalability #APIReliability #BusinessAndTechnology #EngineeringPatterns Keep every episode free: buymeacoffee.com/fexingo
Other episodes covering the same guests and topics, from across The B2B Podcast Index.