More
More
429 Too Many Requests
The client sent too many requests in a given time and is being rate limited.
- Code
429- Reason phrase
- Too Many Requests
- Class
- 4xx Client error
- Defined in
- RFC 6585 section 4
- Cacheable by default
- No
What it means
Client error: the problem lies with the request. Repeating it unchanged will normally fail again.
When a server should send it. When a client has sent too many requests in a given time. Add Retry-After with the seconds to wait (or a date), and say which limit was hit in the body or in rate-limit headers.
Common causes. Scripts or apps calling an API in a tight loop, scrapers, or many users behind one shared address.
What to do. Slow down and retry after the time in the Retry-After header, with exponential backoff in code.
How clients and crawlers treat it
Browsers and HTTP clients. Browsers show the body. Well-behaved API clients and crawlers back off, ideally honouring Retry-After and adding exponential backoff with jitter.
Google Search. Treated as a sign the server is overloaded, like a server error: Googlebot slows its crawl rate. URLs that keep returning 429 are eventually dropped from the index. Source: Google Search Central, How HTTP status codes, and network and DNS errors affect Google Search.
Caching. Not cacheable by default (RFC 9110 section 15.1 does not list it). A cache stores it only when the response says so with Cache-Control or Expires.
Example response
HTTP/1.1 429 Too Many Requests Retry-After: 120 Content-Type: text/plain Too Many Requests
How to send 429
location /example {
add_header Retry-After '120' always;
return 429;
}
Header always set Retry-After "120" RewriteEngine On RewriteRule ^example$ - [R=429,L]
header('Retry-After: 120');
http_response_code(429);
echo 'Too Many Requests';
exit;
res.writeHead(429, { 'Retry-After': '120', 'Content-Type': 'text/plain' });
res.end('Too Many Requests');
# in a view function
return 'Too Many Requests', 429, {'Retry-After': '120'}
Change the paths to suit. In nginx, add_header needs always to apply to error responses.
Related codes
- 503Service UnavailableThe server cannot handle the request right now.
- 403ForbiddenThe server understood the request but refuses it.
- 418I'm a teapotAn April Fools' joke from RFC 2324: a teapot refusing to brew coffee. It is reserved, not a real status.
All status codes · All 4xx codes
Names and numbers from the IANA HTTP Status Code Registry. Google Search behaviour as documented by Google Search Central.