Answer
A client over its rate limit should get HTTP status 429, ideally with a Retry-After header saying when to try again.
Also accepted: 429 Too Many Requests, Too Many Requests for 429.
Why
Many APIs also send the limit, the remaining count and the reset time in headers (such as RateLimit-Limit and RateLimit-Remaining), so well-behaved clients slow down before they are rejected.