Design a login endpoint that limits how many attempts a client can make, to slow down password-guessing.
Design the backend for a login endpoint that must resist password guessing. If anyone can try passwords as fast as they like, an attacker can brute-force accounts. The endpoint therefore needs to limit how many login attempts a client may make in a given window.
The one idea this design introduces is a rate limiter on an incoming path: place a rate limiter in front of the application servers so that excess login attempts from a client are rejected before they reach the login logic. Build on the basic web-app shape and add the limiter between the load balancer and the application tier.
Lay out the architecture, then document the API and the trade-offs, such as choosing a limit that stops attackers without locking out legitimate users who mistype a password.