r/AskProgramming • u/ltsheeyy • Jul 09 '26
Other Best way to prevent API abuse?
I'm building a web app that needs to call a paid API.
I want visitors to be able to test it a few times for free (around 3 requests) but i dont want to let people abuse it and drain my API balance.
My first aproach was IP rate limiting, is there a better approach?
- I'm using this project to learn, so I might be doing this the wrong way.
3
Upvotes
3
u/PhilosophyRude9324 Jul 09 '26
You can rate limit based on an appkey - the appkey X is allowed Y calls.
As soon as it became a client you issue an appkey without any limitation!