Brute force protection with Redis

Protect against brute force attacks by enabling config.brute_force_protection and the redis strategy. This will return an 429 Too Many Requests error after the fourth failed login attempt.

For a complete tutorial, see Protect against brute force attacks with basic authentication.

Prerequisites

  • A Consumer with a username and password

Environment variables

  • REDIS_HOST

  • REDIS_PASSWORD

Set up the plugin

Something wrong?

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!