# Security: Helmet & Rate Limiting — Express.js Fundamentals: Routing, Middleware and APIs

Source: https://www.geekswithgeeks.com/en/expressjs/ex-security-middleware

> Harden an Express API with Helmet security headers, express-rate-limit and a small request body size limit.

## Helmet and rate limiting

`helmet` sets protective HTTP headers and `express-rate-limit` caps requests per client.

```javascript
import helmet from 'helmet';
import rateLimit from 'express-rate-limit';

app.use(helmet());
app.use(express.json({ limit: '100kb' }));
app.use(rateLimit({ windowMs: 15 * 60 * 1000, limit: 100 }));
app.disable('x-powered-by'); // helmet does this too
```

Behind a proxy or load balancer set `app.set('trust proxy', 1)` so rate limits use the real client IP, and always validate input.

Quick check

**Quiz:** What does the helmet package do?

- [x] Sets protective HTTP security headers
- [ ] Parses JSON bodies
- [ ] Connects to MongoDB
- [ ] Compresses images

*Answer:* Sets protective HTTP security headers. Helmet applies a set of secure default headers.
