OWASP API4 & IETF Rate-Limit Header Engine
API Rate Limit & Header Analyzer
Inspect HTTP response headers to evaluate API throttling policies, quota limits, remaining requests, and retry delays. Defend against unrestricted resource consumption and brute-force abuse.
API Rate Limit & Header Analyzer
OWASP API4 / RFC DraftInspect IETF standard, X-RateLimit, and Retry-After HTTP headers to evaluate API throttling, burst limits, and DoS defense posture.
Presets:
IETF RFC Draft RateLimit Header Field & OWASP API Security Top 10 API4:2023.
HTTP/1.1 & HTTP/2 Probe
IETF & Vendor Quota Parsing
Dissects RateLimit-Limit, RateLimit-Remaining, X-RateLimit-*, and Retry-After headers.
Edge WAF & Gateway Detection
Detects upstream edge proxies including Cloudflare, AWS CloudFront, and Fastly to verify Layer-7 traffic protection.
OWASP API4:2023 Compliance
Flags unthrottled endpoints prone to automated credential stuffing, token exhaustion, and denial of service.