API abuse controls: bound the cost of each request
Bound concurrency, task budgets and third-party costs for exports, messaging, image jobs and AI calls.
Contents of this article
Low request rates can still be costly
One request can trigger many queries, large processing jobs or paid downstream calls. OWASP API4 addresses unbounded resource consumption. Fixed bandwidth and unmetered traffic do not cap database, messaging or model costs.
Set limits for each resource
Define page size, upload size, execution time, concurrent jobs, queue length and downstream budgets separately. Make exports asynchronous where appropriate and ensure cancellation stops backend work. Derive limits from normal usage rather than one universal threshold.
Combine identity quotas and network controls
Shared egress and changing source addresses make IP-only controls incomplete. Apply account, tenant, key and operation quotas with network signals. Validate object permissions and idempotency for expensive actions.
Alert on cost as well as traffic
Track downstream cost, queue delay, retries and tenant resource share. Test clear limit responses, continued service for other tenants and bounded retries, with a defined recovery path after degradation.
