Ch. 19 · System Design

System Design Rate Limiting and Fairness

System Design Rate Limiting and Fairness. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readintermediateupdated Oct 3, 2026

Rate limits constrain traffic by a chosen identity and time model. Bursts, distributed enforcement and shared identities affect fairness.

Before you start

You should understand API requests, storage and basic capacity estimates. Begin with a concrete user action and its correctness requirement. Draw data flow and failure boundaries before selecting infrastructure; a technology name by itself does not explain why a design meets the requirement.

The practical goal is to reason through this situation: A token bucket permits bounded bursts while limiting sustained use. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Choose fairness identity

User, tenant and IP correspond to different abuse boundaries.

Step 2: Define burst behavior

A token bucket permits bounded bursts while limiting sustained consumption.

Step 3: Coordinate enforcement

Distributed counters and outage policy affect practical guarantees.

Worked scenario

A token bucket permits bounded bursts while limiting sustained use.

A school shares one public IP across hundreds of candidates. A strict per-IP limit can block legitimate users together. Authenticated user limits can improve fairness, but anonymous abuse and expensive tenant-wide operations may need additional dimensions. State how the system handles unknown identity and limiter-store failure.

Common mistake

A per-IP rule can penalize many legitimate users behind one network.

Verify the behavior

Test bursts, shared networks and distributed concurrent requests against the policy.

Interview exercise

Choose a limiter key.

Answer and reasoning

Combine the actual abuse boundary and authenticated identity where appropriate, with explicit handling for anonymous and shared clients.

Continue learning

Compare the scenario with the System Design interview questions and test your understanding with the System Design MCQs. For terminology and implementation details, consult the reference material.

More in System Design

read ✓System Design · hard

System Design: Bloom Filters

Use a Bloom filter to skip lookups with a tiny memory footprint, and understand its false-positive-only guarantee.

~2 min readread →
read ✓System Design · hard

System Design: Idempotent APIs

Make retried requests safe with idempotency keys, store the result per key, and return the original response on a repeat.

~2 min readread →
esc