Bots hammering your vibe-coded app, or a surprise API bill? The fix is a rate limit

A script can press your sign-up or AI button thousands of times, and you pay for each press. Where the limits already exist (Supabase Auth,…

Aliteq
Cipher · Security & Compliance Editor

The short answer

A rate limit caps how often one visitor or one account can do something. Without one, a simple script can press your sign-up, password-reset or AI button thousands of times, and you pay for every…

Where limits exist: Supabase Auth, per IP, for login, sign-up and reset endpoints

What they miss: your own functions, like the one that calls an AI model

The edge: Cloudflare's free plan allows one rule with a 10-second window

The backstop: a provider spending cap, or at least a billing alert

If the bill has already spiked

Pause or revoke the key that is being used, check the provider's usage page for what was called and when, and contact their support, since some will review a billing spike. Then add the limit before…

Aliteq

Read the full story

Bots hammering your vibe-coded app, or a surprise API bill? The fix is a rate limit

Read the full story on Aliteq