---
title: "Rate limit response headers · Sitebulb Labs"
description: "RateLimit headers let an agent pace itself instead of discovering your limit by hitting it."
url: https://labs.sitebulb.com/docs/checks/protocol-discovery/rate-limit-headers/
---

# Rate limit response headers

RateLimit headers let an agent pace itself instead of discovering your limit by hitting it.

- Category

  [Protocol discovery](https://labs.sitebulb.com/docs/checks/protocol-discovery)

- Standard

  Recommended

## What it checks

The extension fetches the page being scanned and looks at the response headers for any of these:

- `RateLimit`
- `RateLimit-Policy`
- `RateLimit-Limit`
- `X-RateLimit-Limit`
- `X-Rate-Limit-Limit`
- `Retry-After`

The first three are the IETF standard fields and their earlier draft form; the `X-` names are the long-standing convention. Any one of them is enough to pass.

## Results

| Status   | When                                           |
| -------- | ---------------------------------------------- |
| **Pass** | At least one of the headers is on the response |
| **N/A**  | None of the headers is on the response         |

## How to fix

On API responses, send the standard fields so an agent knows its quota and how much of it is left:

```http
RateLimit-Policy: "default";q=100;w=60
RateLimit: "default";r=42;t=18
```

When you reject a request for going over the limit, answer `429 Too Many Requests` with a `Retry-After` header giving the number of seconds to wait.

The check reads the URL you scan, so scan an API endpoint to test your API’s headers rather than a marketing page.
