Ask HN: How to protect public APIs from bots when using a BaaS?
If you build your own backend, you could put a gateway like Kong or similar in front —to detect and throttle/ban robotic usage patterns.
But how do you achieve this if you use Firebase, Graphcool, or another Backend As A Service (BaaS)?
You could deploy a proxy/gateway, but that would incur in an extra hop (= latency) for every single call.
EDIT: Actually, this question is applicable to any API, not just public ones. For private APIs restricted by login, the bot would simply have to create a user first.