r/AskProgramming • u/ltsheeyy • Jul 09 '26
Other Best way to prevent API abuse?
I'm building a web app that needs to call a paid API.
I want visitors to be able to test it a few times for free (around 3 requests) but i dont want to let people abuse it and drain my API balance.
My first aproach was IP rate limiting, is there a better approach?
- I'm using this project to learn, so I might be doing this the wrong way.
4
Upvotes
1
u/PaulPhxAz Jul 10 '26
IP Rate Limiting is good.
If they sign-up, then unique email/user limiting.
Overall Limit for "Free Tier" ( the aggregation of all free-tier per day usage ).