Why does a fixed-window counter allow 2× the rate limit?
If the limit is 100 requests per minute, a caller can send 100 requests at 0:59 and 100 more at 1:01—both inside separate minute windows, yet 200 requests arrived in 2 seconds. This boundary burst is the fundamental flaw in fixed-window rate limiting and why APIs like Stripe moved to token buckets.
Answered in
Token Buckets: Bounding Rate Limits at the EdgeFixed-window counters leak at boundaries. Token buckets refill steadily, absorb bursts, and bound the sustained rate strictly—the algorithm Stripe uses.
Read the full analysisOther questions this article answers
More system design questions
- Why doesn't Google just run Dijkstra faster?
- What is a shortcut edge and when is it precomputed?
- How much space do shortcut edges take compared to the original graph?
- Can Contraction Hierarchies handle dynamic graphs like traffic or road closure?
- Why contract low-degree nodes first instead of high-degree ones?
- What is a CRDT and why does it matter for real-time collaboration?
- How do CRDTs handle concurrent edits without a central server referee?
- Why did Figma move from operational transforms to CRDTs?
Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the System Design beat.