Your API doesn't need to be hacked to become expensive. If a bot can hit an expensive endpoint 50...Your API doesn't need to be hacked to become expensive. If a bot can hit an expensive endpoint 50...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Your API doesn't need to be hacked to become expensive.
If a bot can hit an expensive endpoint 50,000 times, you could end up paying for the damage even though your authentication is working perfectly.
I see SaaS teams put a lot of effort into protecting passwords and auth tokens, while overlooking things like rate abuse, brute-force requests, and automated scraping.
For a Laravel + Vue application, these are some of the things I'd put in place:
Rate-limit the expensive stuff
Don't use the same limit for every endpoint.
A search endpoint might allow 60 requests/minute, while an endpoint that generates PDFs or triggers an AI workflow should have a much tighter limit.
Laravel's RateLimiter makes it easy to define limits based on the user, route, subscription, or other conditions.
For example:
Free users: 30 requests/minute Paid users: 200 requests/minute Expensive AI/PDF operations: much stricter limits
Redis is a good choice when you're running multiple application servers.
Protect SPA authentication properly
If your Vue frontend talks to Laravel through Axios or Inertia, Laravel Sanctum's cookie-based authentication is usually a better fit than storing JWTs in localStorage.
Sanctum + Laravel's CSRF protection gives you a solid foundation for browser-based authentication without having to build your own token storage system.
Don't return your Eloquent models blindly
This: return $user;
might work, but it can also expose fields that your frontend never needed.
Use API Resources to explicitly control what gets returned:
return new UserResource($user);
That makes your API response intentional and reduces the chance of accidentally exposing internal fields.
Validate everything coming from the client
Don't trust request payloads just because they came from your own Vue application.
Use Form Requests to handle validation before your business logic runs.
Validate things like:
UUIDs maximum lengths allowed values required fields numeric ranges file types and sizes
Your frontend validation is for user experience. Your backend validation is for security and correctness.
The important part is that API security isn't just about authentication.
It's also about controlling what can be called, how often it can be called, what data can be returned, and what the server is allowed to process.
If you're building a Laravel web application, these are things worth thinking about before the API starts getting real traffic.
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started