Skip to content
Crafzo
Menu

For developers

Rate Limiting by IP in Node.js: What You Need to Know First

A practical guide to IP-based rate limiting in Node.js — covering express-rate-limit, proxy trust, shared IPs, and when IP limits are not enough.

Updated
Reading time
2 min read

Basic Express setup

A simple TypeScript setup with `express-rate-limit` can protect public endpoints quickly: `app.use(rateLimit({ windowMs: 60_000, limit: 100, standardHeaders: true, legacyHeaders: false }));`. Start with conservative limits and monitor real traffic before tightening them.

Rate limits should match endpoint cost. A login endpoint, password reset flow, search API, and static page do not need the same threshold or response behavior.

Proxy trust and shared IPs

If your Node.js app sits behind a proxy, configure Express with the correct trust setting, such as `app.set("trust proxy", 1)` when there is exactly one trusted proxy hop. Without this, `req.ip` may show the load balancer instead of the client.

Be careful with CGNAT, offices, schools, and public Wi-Fi because many legitimate users can share one IP. A strict IP-only limit can accidentally block unrelated people.

Beyond IP-only limits

Combine IP limits with account, API token, session, device, route, and organization limits. Authenticated APIs often work better with token or account limits, while anonymous endpoints still benefit from IP throttling.

Choose a fixed window for simple protection or a sliding window/token bucket for smoother behavior. Use Crafzo during investigations to understand whether a noisy IP is residential, mobile, hosting, VPN, or already risky.

Frequently asked questions

Keep reading