API abuse controls: bound the cost of each request

Bound concurrency, task budgets and third-party costs for exports, messaging, image jobs and AI calls.

Contents of this article

Low request rates can still be costly

One request can trigger many queries, large processing jobs or paid downstream calls. OWASP API4 addresses unbounded resource consumption. Fixed bandwidth and unmetered traffic do not cap database, messaging or model costs.

Set limits for each resource

Define page size, upload size, execution time, concurrent jobs, queue length and downstream budgets separately. Make exports asynchronous where appropriate and ensure cancellation stops backend work. Derive limits from normal usage rather than one universal threshold.

Combine identity quotas and network controls

Shared egress and changing source addresses make IP-only controls incomplete. Apply account, tenant, key and operation quotas with network signals. Validate object permissions and idempotency for expensive actions.

Alert on cost as well as traffic

Track downstream cost, queue delay, retries and tenant resource share. Test clear limit responses, continued service for other tenants and bounded retries, with a defined recovery path after degradation.

References

OWASP API4:2023

Continue reading

Read related content

Back to industry insights Contact technical support