Gateway Gus saysRate limiting caps how many requests a client can make — protecting the API from overload and abuse.
To stay healthy and fair, APIs limit request rates per client/key (e.g. 100/minute). Exceed it and you get 429 Too Many Requests, often with a Retry-After header and X-RateLimit-* headers telling you your remaining quota. Limits protect against abuse, runaway clients, and cost blowouts. Clients should respect the headers and back off.
Power-ups you unlock
Caps requests per client/key
Over limit → 429 Too Many Requests
Retry-After + X-RateLimit-* headers guide you
Protects against abuse and overload
Timeout Titan attacks — common mistakes
Ignoring 429 and hammering harder
Not reading X-RateLimit-Remaining
No client-side throttling at all
Boss battleDescribe how a well-behaved client reacts to a 429 with Retry-After.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>429 Too Many Requests
Retry-After: 30
X-RateLimit-Remaining: 0
→ wait 30s, then retry</pre></body></html>