Devstars

Devstars Custom web software and digital growth consultancy. Jersey & London. The team at Devstars has a wealth of web industry experience.

We build bespoke platforms, optimise for AI-era search (GEO), and provide fractional CMO direction. 20+ years, clients include Heathrow, MoD, and Dash Rides. Over the years we have grown steadily and during this time nurtured a competent group of highly skilled web developers. We like to get involved from conception to completion and put as much emphasis on our consultancy and management as we do

on the actual build and aftercare. As well as working directly for clients like Royal Academy of Music, Timberland and Cutler and Gross, we increasingly provide programming support for graphic design agencies, advertising agencies and even other web designers. We value our growing and successful list of long-term clients and want to work with you.

09/06/2026

Every student on the platform was locked out. The error said "Too Many Requests." The client assumed their GitHub login had broken.
It hadn't. And neither had GitHub.

Here's what happened yesterday to one of our clients learning platforms. A wave of automated bot traffic was hammering the GitHub OAuth login endpoint. GitHub did exactly what it's designed to do and applied rate limits to that IP. The trouble is, once those limits tripped, real students got knocked back alongside the bots.

Our monitoring picked up thousands of malicious requests during the incident, from IP addresses across multiple countries. (geolocation shows where traffic appears to come from, not who's behind it. But it tells you how global and automated this stuff has become.)

We could have switched off GitHub login or added friction across the whole platform. Both punish your real users for a problem they didn't cause.

So we went targeted instead. A single Cloudflare Managed Challenge on the OAuth redirect. Real people pass a quick check and carry on. Bots get filtered out before they ever reach the authentication flow.

Result: access restored the same day. No changes to the client's app. No changes to their GitHub setup.

The lesson for anyone running an AI or tech platform: the best security fixes usually stop the bad traffic before it reaches the services you depend on.

Use the right rule, the right tools and in the right place, and you protect your users and your dependencies in one move.

Seeing rate limit errors at a third-party login? Don't assume the integration's broken. Check your IP's rate limit status first.

If you have a problem, if no one else can help, and if you can find them, maybe you can hire the A-Team! If not give us a call 😀

https://www.devstars.com/blog/githubs-too-many-requests-error/

hashtag hashtag hashtag hashtag hashtag hashtag

15/05/2026

When you live on an island, you have to love the sea. My family and I are at the beach several times a week. Sea swimming, paddleboarding, kayaking, a bit of

Address

Ground Floor, Digital Hub, Forum 4, Block 3 Grenville Street
London
JE24UF

Opening Hours

Monday 9am - 6pm
Tuesday 9am - 6pm
Wednesday 9am - 6pm
Thursday 9am - 6pm
Friday 9am - 6pm

Telephone

+442088983993

Alerts

Be the first to know and let us send you an email when Devstars posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Devstars:

Share