Learning on Web Dev Open is free for all.

Interview Prep · System DesignDesign a rate limiter
← System Design

Design a rate limiter

Easy35 minFree, no account

Four algorithms, one of which is right, and a counter that lives in the wrong place.


The question

Design a rate limiter for a public API: 1,000 requests per user per hour, enforced across a fleet of servers.

Be specific about where the counter lives and what happens when that store is unavailable.

Functional
  • Reject requests over the limit with 429 and a Retry-After header.
  • Limits are configurable per endpoint and per plan.
  • A caller can see their remaining quota.
Non-functional
  • 50,000 requests/sec across the fleet.
  • Adds under 5ms to a request at p99.
  • A failure in the limiter must not take down the API.
35:00Commit to an answer before you open the solution. Reading it first teaches you to recognise good answers, which is not the skill being tested.

Stuck?

0 of 3 hints taken

The worked solution

written by a person · not a grade

Score yourself

0 of 4 marked
  • Compared the algorithms and justified one, not just named them20
  • Made the counter update atomic and explained the race it avoids30
  • Addressed the latency cost, with local leases or an equivalent25
  • Chose a failure mode deliberately and said which endpoints get which25

We run no AI here and nothing on this page grades you. The score is yours, and the useful number is the one you get on the same problem a month from now, cold.

kept in this browser only