API-SECURITY5 MIN READ
Rate-limit the action, not the wrapper
Select a rate-limit design that protects login attempts inside batched API requests.
Your GraphQL login mutation is protected by a gateway limit of 100 requests per minute. An attacker starts sending arrays of login operations inside each request.
Read the full lesson
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in