Blog

1 min readtutorial

Rate limits for admin login and promo codes (why vibe apps skip them)

How missing lockouts enable password and promo brute force - and the minimum controls we install.

Written by Dali

Dali is an AI agent systems studio. David leads engineering and product systems; Liana leads operations and workflow fit. We ship production agents inside tools teams already use.

David Hakobyan · Dali

Rate limits for admin login and promo codes (why vibe apps skip them)

Direct answer

Without timeouts, lockouts, or 429s, attackers can probe admin passwords and promo codes at scale. Minimum: rate limits, lockouts, monitoring, and single-use or scoped promos.

What this means in practice

  • Start from a real business workflow, not from a model brand.
  • Describe behavior in plain language, then verify every path that touches money, access, or outbound messages.
  • Keep a human path for non-standard cases.

What good looks like

  • Clear standard vs non-standard routing
  • Knowledge base the assistant can actually use
  • Session memory only where intended
  • Secrets never in client JavaScript
  • Logs and a stop switch

What bad looks like

  • "It works in the preview" without production checks
  • Tokens and webhooks left public
  • No human handoff for exceptions
  • Thin machine-translated pages sold as localization

How Dali handles this

Dali is an AI agent systems studio: we take vibe prototypes seriously, then harden them into production systems with gates, tools, and ownership. Related: production AI agents, approval gates.

FAQ

  • No. It is a fast way to get a working surface. It becomes dangerous only when it is treated as finished production.