Rate-limit message (429)
Also called: 429 Too Many Requests, too many requests message, rate limit error, cooldown message.
What the user sees when the server says "too many requests, slow down" (HTTP status 429). A good one says in plain words how long to wait, often with a countdown taken from the Retry-After header.
The server allows 3 codes every 15 s. Tap “Resend code” 4 times: the 4th gets 429 Too Many Requests with Retry-After. The friendly message turns that into plain words and a countdown.
Ready
Say it in a prompt
When POST /login/code/resend returns 429, read the Retry-After header and show "Too many codes asked for. You can ask for a new one in 30 s." under the button. Disable "Resend code" with a live countdown, and enable it again when the countdown reaches 0. Seen on
- GitHub REST API: Over the limit it answers 403 or 429, with retry-after or x-ratelimit-reset saying when you may try again.
- Stripe API: Rate-limited requests get 429 Too Many Requests and a Stripe-Rate-Limited-Reason header that says which limit was hit.
You might describe it as
- too many attempts, try again in 30 seconds
- error when I click resend too many times
- countdown before I can ask for another code
Not to be confused with
- Retry with backoff
A rate-limit message tells the person how long to wait; retry with backoff is code that waits and tries again on its own.