Requests pour into a fixed-capacity bucket while the bucket drains (“leaks”) at a constant rate. A request that arrives with room in the bucket is accepted and queued; if the bucket is already full it overflows and is rejected. Steady leaking smooths bursts into a constant outflow — unlike fixed windows, there is no hard reset boundary.