0Pricing
Node.js Backend Development Bootcamp · Lesson

Rate Limiting & Brute-Force Protection

Defend your Node.js APIs against abuse, denial-of-service, and credential-stuffing attacks by implementing rate limiting and brute-force protection.

Rate Limiting & Brute-Force Protection is a free Node.js Backend Development Bootcamp lesson on CoddyKit — lesson 4 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Node.js Backend Development Bootcamp learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Why Limit Requests?

Without limits, a single client can hammer your API thousands of times per second — scraping data, guessing passwords, or simply overloading the server.

Rate limiting caps how many requests a client may make in a time window.

Attacks Rate Limiting Prevents

Rate limiting is a frontline defense against:

  • Brute-force login attempts
  • Credential stuffing with leaked passwords
  • Denial-of-service floods
  • Scraping and API abuse

How Counting Works

A rate limiter tracks a counter per client (usually keyed by IP). Each request increments it; when the count exceeds the limit within the window, further requests are rejected with 429 Too Many Requests.

express-rate-limit

The express-rate-limit package adds rate limiting as middleware in a few lines. Configure the window and max requests.

const rateLimit = require('express-rate-limit');
const limiter = rateLimit({
  windowMs: 15 * 60 * 1000,
  max: 100
});

Applying the Limiter

Apply globally with app.use, or to specific routes. Once over the limit, clients automatically receive a 429 response.

app.use(limiter);
// or just protect one route:
app.use('/api/', limiter);

Stricter Limits on Login

Login endpoints are prime brute-force targets, so give them a tighter limit than the rest of your API.

const loginLimiter = rateLimit({
  windowMs: 10 * 60 * 1000,
  max: 5,
  message: 'Too many login attempts'
});
app.post('/login', loginLimiter, handler);

Shared Store for Multiple Servers

The default in-memory store does not work when you run multiple instances behind a load balancer — each has its own counter. Use a shared store like Redis so limits apply across all servers.

const RedisStore = require('rate-limit-redis');
const limiter = rateLimit({
  store: new RedisStore({ /* client */ }),
  max: 100,
  windowMs: 60000
});

Trusting the Real Client IP

Behind a proxy, every request appears to come from the proxy's IP. Tell Express to trust the proxy so the limiter keys on the real client IP from X-Forwarded-For.

app.set('trust proxy', 1);

Account Lockout

Beyond IP limits, track failed logins per account. After several failures, temporarily lock the account or require a CAPTCHA — defeating distributed brute-force from many IPs.

if (user.failedAttempts >= 5) {
  return res.status(423).json({ error: 'Account locked' });
}

Slowing Down Instead of Blocking

An alternative to hard blocks is progressive delay: each repeated request waits a little longer. The express-slow-down package adds latency rather than rejecting outright.

const slowDown = require('express-slow-down');
const speedLimiter = slowDown({
  windowMs: 60000,
  delayAfter: 50,
  delayMs: () => 500
});

Informing Clients

Good limiters send RateLimit headers telling clients their remaining quota and reset time, so well-behaved apps can back off gracefully.

const limiter = rateLimit({
  max: 100,
  windowMs: 60000,
  standardHeaders: true
});

Quick Check

Test your rate-limiting knowledge.

Recap

You learned to protect APIs from abuse:

  • Rate limiting caps requests per client and returns 429 when exceeded
  • express-rate-limit adds it as middleware; use stricter limits on login
  • Use a Redis store across multiple servers and set trust proxy for real IPs
  • Add account lockout, progressive slow-down, and informative headers

These layers thwart brute-force, scraping, and DoS attacks.

Frequently asked questions

Is the “Rate Limiting & Brute-Force Protection” lesson free?

Yes — the full text of “Rate Limiting & Brute-Force Protection” is free to read here on the web, and the Node.js Backend Development Bootcamp course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Node.js Backend Development Bootcamp course, upgrade to CoddyKit PRO.

What will I learn in “Rate Limiting & Brute-Force Protection”?

Defend your Node.js APIs against abuse, denial-of-service, and credential-stuffing attacks by implementing rate limiting and brute-force protection. You practise Node.js Backend Development Bootcamp with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Node.js Backend Development Bootcamp?

No prior experience is required. Node.js Backend Development Bootcamp on CoddyKit is structured for beginners through advanced learners; this is — lesson 4 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “Rate Limiting & Brute-Force Protection” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Node.js Backend Development Bootcamp lesson?

Yes. Every Node.js Backend Development Bootcamp lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Understanding OWASP Top 10
  2. Secure Coding Practices in Node.js
  3. Data Encryption & Hashing
  4. Rate Limiting & Brute-Force Protection
← Back to Node.js Backend Development Bootcamp