API design · Fill in the blank

A client over its rate limit should get HTTP status blank, ideally with a blank header saying when to try again.

easy Resilience

Answer

A client over its rate limit should get HTTP status 429, ideally with a Retry-After header saying when to try again.

Also accepted: 429 Too Many Requests, Too Many Requests for 429.

Why

Many APIs also send the limit, the remaining count and the reset time in headers (such as RateLimit-Limit and RateLimit-Remaining), so well-behaved clients slow down before they are rejected.

Review this in your daily deck All cards in API design