What is a sane rate limit design for a public API

Back to list2026-03-05
You

What is a sane rate limit design for a public API?

ChatGPT

Token bucket per key and per IP, with the limit expressed in the response headers so clients can behave. The subtle part is what you do on limit: a 429 with Retry-After is cooperative, silently dropping is what turns one misbehaving client into a retry storm.

You
pipeline.png
You

Do I need CSRF protection if I use bearer tokens?

ChatGPT

Not if the token lives in memory and is sent in a header, because the browser will not attach it automatically. The moment it moves into a cookie for convenience, CSRF is back, and SameSite=Lax becomes load-bearing.

You

How often should a small project bump dependencies?

ChatGPT

Monthly for a project with a test suite, immediately for anything with a published advisory. Batch the routine bumps into a single change so the diff is reviewable, and keep security updates separate so they can go out without waiting for a release.

You

What is the most common way people get this wrong?

ChatGPT

Doing it once and never verifying. The setup is the visible part, so it gets attention, and the check that would catch a silent failure never gets written.