Rate limit response headers

RateLimit headers let an agent pace itself instead of discovering your limit by hitting it.

Standard
Recommended

What it checks

The extension fetches the page being scanned and looks at the response headers for any of these:

  • RateLimit
  • RateLimit-Policy
  • RateLimit-Limit
  • X-RateLimit-Limit
  • X-Rate-Limit-Limit
  • Retry-After

The first three are the IETF standard fields and their earlier draft form; the X- names are the long-standing convention. Any one of them is enough to pass.

Results

Status When
Pass At least one of the headers is on the response
N/A None of the headers is on the response

How to fix

On API responses, send the standard fields so an agent knows its quota and how much of it is left:

RateLimit-Policy: "default";q=100;w=60
RateLimit: "default";r=42;t=18

When you reject a request for going over the limit, answer 429 Too Many Requests with a Retry-After header giving the number of seconds to wait.

The check reads the URL you scan, so scan an API endpoint to test your API’s headers rather than a marketing page.