A rate limit is a cap on how often you may call an API — usually expressed per second, per minute, or per hour. Exceed it and the API stops answering, normally with HTTP 429 Too Many Requests.
It is not the same thing as a quota, and conflating the two is how people end up surprised twice.
Rate limit or quota?
| Measures | Resets | You hit it when | |
|---|---|---|---|
| Rate limit | Calls per unit of time | Continuously | You go fast |
| Quota | Calls per billing period | Monthly or daily | You go far |
A generous quota with a tight rate limit means you can make a million calls this month, but not in one afternoon. A tight quota with no rate limit means you can burn the month in an hour. Read both before you write the loop.
The limit you hit is rarely the one advertised
Three things move the real ceiling below the published number:
- Per-endpoint limits. A provider may advertise 100 requests/minute overall and enforce 10/minute on the expensive route.
- Concurrency limits. Some APIs cap simultaneous open connections rather than calls per minute. Ten workers at one call each is different from one worker at ten.
- Burst buckets. A token bucket lets you spend a burst and then throttles you far below the average. The published figure is the refill rate, not what you get in the first second.
What to do when you get a 429
Respect the Retry-After header if there is one. If there is not, back off exponentially with jitter — fixed-interval retries from many workers re-synchronise and hit the wall together.
attempt 1 → wait 1s + random(0–1s)
attempt 2 → wait 2s + random(0–2s)
attempt 3 → wait 4s + random(0–4s)
What not to do is retry immediately in a loop. On some providers that converts a temporary 429 into a longer block.
The failure worth designing for
A 429 is honest — it tells you what happened. The dangerous case is a provider that answers 200 with partial or empty data when you push too hard, because nothing in your code notices. That is a silent failure, and it is the reason we publish a never-cached status page rather than an uptime badge.
Our own limit is published with the pricing: one credit per call, and a call that finds nothing costs nothing.