429 Too Many Requests means a rate limit was reached: one visitor, address or API key sent more requests in a short time than the server allows. It is a deliberate block, usually temporary.
If you are visiting the site or using an API
- Wait. Many responses include a
Retry-Afterheader saying how many seconds. - If you are calling an API, slow your requests and retry with increasing gaps (exponential backoff).
- On a shared network or VPN, many people share your address and use up the limit together.
If you run the site
1. Find where the limit is set
A 429 can come from any layer: the CDN, a web application firewall, Nginx’s limit_req, a security plugin, or the app itself. The response headers and the error page’s branding usually show which.
2. Nginx rate limits
limit_req_zone $binary_remote_addr zone=perip:10m rate=10r/s;
server {
location / {
limit_req zone=perip burst=20 nodelay;
limit_req_status 429;
}
}
rate is the steady allowance; burst lets short spikes through. A page that loads many files can trip a strict limit on its own; apply limits to sensitive paths like logins rather than the whole site.
3. Behind a CDN, use the real visitor IP
If every request appears to come from the CDN’s addresses, everyone shares one limit. Configure the server to trust the CDN’s header for the real IP, for example Nginx’s real_ip_header and set_real_ip_from.
4. Check whether it is an attack
If one address is sending thousands of requests to a login page or search, the limit is doing its job. Consider blocking that address at the firewall.
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.



