A token bucket refills at a fixed rate up to its capacity. Each request spends a token; with none left, the request waits or is rejected. Stored tokens permit a short burst above the refill rate.
The demo spends tokens as requests arrive and refills them over time. A production API also needs a caller key, atomic updates in shared storage, and useful retry guidance after rejection.
When to use
Use it to curb API abuse while still accepting brief bursts from legitimate callers.