Skip to main content
vly’s API has built-in rate limits per key. For your app’s user-facing endpoints (login, signup, public forms), implement application-level rate limits to defend against abuse. The pattern lives in Architecture → Rate limiting. Quick summary:

Where to apply

Tips

Combine with CAPTCHA. Rate limits stop bulk abuse; CAPTCHA stops sophisticated attackers who use slow drips.
Log rate-limit hits. Repeated hits from the same IP may indicate a coordinated attack.

Architecture: rate limiting

Implementation.

Auth best practices

Where rate limits matter most.

API rate limits

vly’s built-in API limits.
Last modified on April 18, 2026