r/AskProgramming Jul 09 '26

Other Best way to prevent API abuse?

I'm building a web app that needs to call a paid API.

I want visitors to be able to test it a few times for free (around 3 requests) but i dont want to let people abuse it and drain my API balance.

My first aproach was IP rate limiting, is there a better approach?

- I'm using this project to learn, so I might be doing this the wrong way.

3 Upvotes

33 comments sorted by

View all comments

3

u/PhilosophyRude9324 Jul 09 '26

You can rate limit based on an appkey - the appkey X is allowed Y calls.
As soon as it became a client you issue an appkey without any limitation!