Rate limitinghard5-8 years

Compare token bucket and sliding-window-counter rate limiting. Which would you reach for on a public API, and why?

Token bucket refills tokens at a steady rate up to a capacity, and a request spends one — it allows a burst up to the bucket size and then enforces the average rate. A sliding window counter blends the current and previous fixed windows' counts, weighted by how much of the previous window still overlaps the trailing period — smoother than a fixed window (no double-burst at the boundary) at the cost of more state, and it's still an estimate, not an exact count. Token bucket usually wins for a public API because real clients are legitimately bursty — a page load firing six requests at once — and what you actually want to bound is the sustained rate, not a brief clump.

The lesson behind it →