Rate limits
Rate limiting protects finite resources from automation, and where you apply it decides what it protects.
Per IP is trivially defeated. Per account catches abuse of a single login. Per endpoint protects the expensive operation. Global limits protect the platform and punish everybody equally during an attack. Most implementations pick one and discover the gaps later.
Checked against the primary source.
