Rate limit response headers
RateLimit headers let an agent pace itself instead of discovering your limit by hitting it.
- Category
- Protocol discovery
- Standard
- Recommended
What it checks
The extension fetches the page being scanned and looks at the response headers for any of these:
RateLimitRateLimit-PolicyRateLimit-LimitX-RateLimit-LimitX-Rate-Limit-LimitRetry-After
The first three are the IETF standard fields and their earlier draft form; the
X- names are the long-standing convention. Any one of them is enough to pass.
Results
| Status | When |
|---|---|
| Pass | At least one of the headers is on the response |
| N/A | None of the headers is on the response |
How to fix
On API responses, send the standard fields so an agent knows its quota and how much of it is left:
RateLimit-Policy: "default";q=100;w=60
RateLimit: "default";r=42;t=18
When you reject a request for going over the limit, answer 429 Too Many Requests with a Retry-After header giving the number of seconds to wait.
The check reads the URL you scan, so scan an API endpoint to test your API’s headers rather than a marketing page.