API Rate Limiting: How HTTP 429, Headers, and Token Buckets Work
Understand API rate limiting algorithms: token bucket, leaky bucket, and sliding window. How to parse X-RateLimit headers and handle HTTP 429 backoff.
Rate limiting protects web servers from noisy neighbors, denial-of-service attacks, and runaway scraping scripts. When a client exceeds their allowance, the server responds with HTTP 429 Too Many Requests.
Standard Rate Limit Response Headers
HTTP/1.1 429 Too Many Requests
X-RateLimit-Limit: 100
X-RateLimit-Remaining: 0
X-RateLimit-Reset: 1728229800
Retry-After: 45
{
"error": "rate_limit_exceeded",
"message": "You have exceeded your quota of 100 requests per minute. Please wait 45 seconds."
}
Well-behaved clients read the Retry-After header and implement exponential backoff with jitter to retry gracefully.