All questions
UberHard· Onsite · Senior · Technical

How would you design a rate limiter?

526 11,240 people practisedUpdated Sep 16, 2026Question 29 of 30
System DesignScalability
Amigo's answer
Your AI interview companion

How to approach it

Clarify requirements first — limits per user or per IP, single server or distributed, how strict. Then walk through an algorithm, where state lives and the trade-offs. Talking through your reasoning matters more than a perfect design.

Example answer

"I'd first confirm the limit — say 100 requests per minute per API key, across multiple servers. I'd use a token bucket: each key gets tokens that refill at a steady rate, and each request spends one. To share state across servers, I'd store buckets in Redis and update them atomically with a Lua script. If Redis is unavailable, I'd fail open for most endpoints but fail closed for sensitive ones like login. Finally, I'd return a 429 with a Retry-After header."
Next question
How do you approach debugging a production issue?