rate limiting
Fixed Window Counter
Divide time into fixed-size windows with a counter per window
Window Counter0 / 5
Window Progress95%
Allowed0
Rejected0
5 req / 4s window
⚠ boundary problem
Try sending 5 requests at the end of one window and 5 more at the start of the next. You'll get 10 requests through in a very short burst — double the limit! This is the fundamental flaw of fixed windows.
// how it works
Time is divided into fixed windows (e.g. 1 minute). Each window has a counter.
- New request arrives → find current window
- If counter < limit → allow, increment counter
- If counter ≥ limit → reject
- Window expires → counter resets to 0
// trade-offs
- O(1) time and space — extremely simple
- Low memory: only 1 counter per key
- Boundary problem: 2× burst at window edges
- Not suitable when smooth rate enforcement is critical