Fixed Window Counter Rate Limiting

5
0

Introduction

Fixed Window Counter is one of the simplest algorithms used to implement rate limiting. It restricts how many requests are allowed during a fixed time interval, such as one minute, one hour, or one day.

The algorithm is easy to understand because it follows a basic rule: count requests in the current window, allow them until the limit is reached, and reject extra requests until the next window begins.

What Is Fixed Window Counter?

Fixed Window Counter divides time into fixed intervals called windows. Each window has a predefined duration, and a counter is maintained for that duration.

For example, if the limit is: 100 requests per IP address per minute

Then every IP address can make up to 100 requests during the current one-minute window. Once the counter reaches 100, additional requests from that IP address are rejected until the next minute starts.

The window duration can vary depending on the requirement:

  • 1 minute: Useful for API request control.

  • 1 hour: Useful for user-level quotas.

  • 1 day: Useful for daily usage limits.

  • Custom duration: Useful when limits depend on product or security rules.

How Fixed Window Counter Works

The working of the algorithm can be understood in a few clear steps.

  • Divide time into windows: Time is split into fixed intervals such as 12:00-12:01, 12:01-12:02, and so on.

  • Define a limit: A rule is configured, such as 100 requests per user per minute.

  • Maintain a counter: Every allowed request increments the counter for the current window.

  • Reject after limit: Once the counter crosses the allowed limit, extra requests are denied.

  • Reset on new window: When the next window starts, the counter resets to zero.

A simple request flow looks like this: Request arrives => Counter is checked => Request is allowed or rejected

If the request is within the limit, it is forwarded to the backend. If the limit has already been reached, the system usually returns: HTTP 429 Too Many Requests

Fixed Window Counter - Rate Limiting Algorithm

Fixed Window Counter - Rate Limiting Algorithm

Rule Keys in Fixed Window Counter

A rate limiter needs to know what it is counting. This is decided using a rule key. The algorithm stays the same, but the key changes based on what the system wants to restrict.

Common rule keys include:

  • User ID: Limits requests made by a logged-in user.

  • IP address: Limits requests coming from the same network address.

  • API key: Limits usage for a specific application or customer.

  • Endpoint: Applies limits to sensitive APIs such as login, OTP, or payment.

  • Combination key: Uses multiple values, such as user ID plus endpoint.

For example, a login API may use stricter limits than a normal read-only API because repeated login attempts can indicate brute-force abuse.

Advantages of Fixed Window Counter

Fixed Window Counter is popular because it is simple and efficient. It does not require storing every request timestamp, which makes it lightweight compared to more precise algorithms.

Main advantages include:

  • Simple logic: Count requests inside a fixed window and compare with the limit.

  • Fast execution: Only a counter update and limit check are needed.

  • Low storage requirement: Usually one counter is enough per key per window.

  • Easy to understand: The rule is clear for both developers and users.

  • Good for basic quotas: Works well when small bursts near boundaries are acceptable.

Because of this simplicity, Fixed Window Counter is often used for basic API rate limits, daily quotas, and simple abuse prevention.

Main Drawback: Boundary Burst Problem

The biggest weakness of Fixed Window Counter is the boundary burst problem. This happens when requests are concentrated near the end of one window and the beginning of the next window.

Suppose the rule is: 100 requests per user per minute

Now consider this traffic pattern:

Time

Requests Sent

Result

Last few seconds of Window 1

100

Allowed

First few seconds of Window 2

100

Allowed

Technically, the user followed the limit in each separate window. But in real time, the system may receive 200 requests within just a few seconds.

This creates a burst that is much higher than the intended rate. The algorithm is not broken, but its fixed reset behavior allows this edge case.

Summary

Fixed Window Counter is a simple rate limiting algorithm that divides time into fixed windows and counts requests inside each window. Once the configured limit is reached, extra requests are rejected until the next window starts.

Its main strengths are simplicity, speed, and low storage usage. Its main weakness is the boundary burst problem, where requests at the end of one window and the start of the next can create a sudden traffic spike. This makes it useful for basic rate limiting, but less suitable when strict and smooth request control is required.

CS Core

Read Similar Blogs

Comments0