Skip to content
Web Security

What is Rate Limiting & HTTP 429?

Server caps on request volume per client or key, answered with status 429 plus a Retry-After hint when exceeded. Limits protect login, signup, and AI endpoints from abuse and runaway costs.

Example

Login and AI-generation routes answer over-budget clients with status 429 and a Retry-After hint. Frontends back off and queue instead of retrying in a tight loop that deepens the overload.

What people get wrong

Returning success statuses with error bodies for throttled calls. Standard 429 responses let clients, proxies, and edge caches cooperate; bespoke signals force every integrator to guess.

Sources

Browse all Web Security terms →