Laravel Rate Limiting

Apply per-user and per-route limits with RateLimiter and throttle middleware; use backoffs and headers for clients

noartem Updated

File contents

Rate Limiting and Throttle

Protect endpoints from abuse while keeping UX predictable.

Commands

// App\Providers\RouteServiceProvider
RateLimiter::for('api', function (Request $request) {
    return Limit::perMinute(60)->by(optional($request->user())->id ?: $request->ip());
});

// routes/api.php
Route::middleware(['throttle:api'])->group(function () {
    // ...
});

Patterns

  • Scope limits by user when authenticated; fall back to IP
  • Communicate limits to clients via standard headers
  • Provide sensible 429 responses with retry hints
  • Separate bursty endpoints into specialized limiters

noartem/laravel-vue-skills/tree/main/skills/laravel-rate-limiting-and-throttle commit 2a350a15ae

Frequently asked questions

npx skillmds@latest add noartem/laravel-rate-limiting