Implement in-memory rate limiter with 5 attempts per 15-minute window per IP address. Protects brute-force attacks on credential endpoints. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>