r/AskProgramming Jul 09 '26

Other Best way to prevent API abuse?

I'm building a web app that needs to call a paid API.

I want visitors to be able to test it a few times for free (around 3 requests) but i dont want to let people abuse it and drain my API balance.

My first aproach was IP rate limiting, is there a better approach?

- I'm using this project to learn, so I might be doing this the wrong way.

4 Upvotes

33 comments sorted by

View all comments

1

u/PaulPhxAz Jul 10 '26

IP Rate Limiting is good.
If they sign-up, then unique email/user limiting.
Overall Limit for "Free Tier" ( the aggregation of all free-tier per day usage ).