429 🌐 HTTP

HTTP 429 Too Many Requests

You’ve hit a rate limit — too many requests in a given time window. Slow down and retry later.

Seen on: JavaScript Python Nginx REST API

Meaning

The server (or an API gateway/CDN in front of it) is throttling you. Well-behaved servers include a Retry-After header and often X-RateLimit-* headers showing your quota. Retrying immediately in a tight loop only makes it worse.

Common causes

  • Exceeding the API’s per-second/minute/day quota
  • Retry loops without backoff amplifying traffic
  • Many clients sharing one API key or one NAT/IP address
  • Burst of parallel requests (Promise.all over hundreds of items)
  • Brute-force protection on login endpoints
  • CDN/WAF rate-limiting rules

⚡ Quick fix

  1. Honor the Retry-After header before retrying
  2. Add exponential backoff with jitter to retries
  3. Limit concurrency (queue requests, e.g. 5 at a time)
  4. Cache responses that don’t change often
  5. Request a higher quota or use separate keys per service

Detailed fix by platform

JavaScript

  1. Retry with Retry-After + exponential backoff:
    javascript
    async function fetchWithRetry(url, opts = {}, attempt = 0) {
      const res = await fetch(url, opts);
      if (res.status !== 429 || attempt >= 5) return res;
      const retryAfter = Number(res.headers.get('Retry-After'));
      const wait = retryAfter ? retryAfter * 1000 : Math.min(30000, 2 ** attempt * 500) + Math.random() * 250;
      await new Promise(r => setTimeout(r, wait));
      return fetchWithRetry(url, opts, attempt + 1);
    }

Python

  1. requests + urllib3 Retry:
    python
    from requests.adapters import HTTPAdapter
    from urllib3.util.retry import Retry
    s = requests.Session()
    s.mount("https://", HTTPAdapter(max_retries=Retry(total=5, backoff_factor=1,
            status_forcelist=[429, 503], respect_retry_after_header=True)))

Nginx

  1. If your own Nginx returns 429/503, review limit_req zone=… burst=… nodelay settings.

How to diagnose

  1. Headers — Retry-After and X-RateLimit-Remaining values?
  2. Volume — How many requests per second are you actually sending?
  3. Scope — Is the limit per key, per user or per IP?
  4. Retries — Are retries multiplying traffic?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.