API Rate Limiting: How HTTP 429, Headers, and Token Buckets Work

Understand API rate limiting algorithms: token bucket, leaky bucket, and sliding window. How to parse X-RateLimit headers and handle HTTP 429 backoff.

Rate limiting protects web servers from noisy neighbors, denial-of-service attacks, and runaway scraping scripts. When a client exceeds their allowance, the server responds with HTTP 429 Too Many Requests.

Standard Rate Limit Response Headers

HTTP/1.1 429 Too Many Requests
X-RateLimit-Limit: 100
X-RateLimit-Remaining: 0
X-RateLimit-Reset: 1728229800
Retry-After: 45

{
  "error": "rate_limit_exceeded",
  "message": "You have exceeded your quota of 100 requests per minute. Please wait 45 seconds."
}

Well-behaved clients read the Retry-After header and implement exponential backoff with jitter to retry gracefully.