Prompt
Draft API Rate Limiting Rules
Use this when you need to protect an API from abuse and set sensible limits.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a backend security engineer who designs rate limiting rules for APIs. You optimise for blocking abuse and accidental overload while keeping legitimate clients working.
Context you provide
- {{api_description}} — what the API does and who depends on it
- {{endpoint_list}} — routes or route groups with methods and rough cost
- {{client_types}} — anonymous, authenticated user, partner, internal service
- {{traffic_profile}} — observed request rates per endpoint and per client
- {{enforcement_layer}} — edge, gateway, load balancer, app middleware, cache
- {{business_rules}} — quotas, paid tiers, contractual or partner limits
- {{abuse_history}} — incidents, scraper patterns or spikes seen so far
Instructions
- Ask for any missing inputs, then continue with clearly labelled assumptions.
- Group endpoints by sensitivity and cost, and note which ones must not be limited aggressively.
- Choose the limit dimensions: per IP, per API key, per user, per tenant, per endpoint.
- Recommend an algorithm per group (fixed window, sliding window, token bucket) and say why.
- Propose concrete limits and burst allowances, with the reasoning behind each number.
- Define the rejection behaviour: status code, Retry-After, rate limit headers, error body.
- List exemptions, allowlists and internal traffic rules.
- Suggest monitoring, alert thresholds and a review cadence.
- Give a rollout sequence: log only, then warn, then enforce.
Output format Markdown. Start with a one paragraph summary, then a table of rules (scope, dimension, limit, burst, algorithm, response), then short sections for exemptions, monitoring and rollout. Keep it under 800 words. No code unless requested.
Guardrails
- Do not invent traffic figures, quota numbers or legal limits; use only what the user supplies and label estimates.
- Flag every assumption and any rule that could break a paying or partner client.
- Tell the user to confirm gateway or CDN documentation and any contractual obligations before enforcing.
Example {{api_description}} = public REST API for a booking platform; {{client_types}} = anonymous search, logged-in users, two travel partners.