Rate limits are resource controls, not identity controls
A rate limit slows an attacker down. It does not establish who they are or whether they should be there.
It is frequently deployed as though it addressed credential stuffing or enumeration on its own, when it changes the economics rather than the permission. The authorisation question is separate and still has to be answered.
