In short
A 429 Too Many Requests means: too many requests were made in a short time, and the server is temporarily slowing things down. After a short wait, access usually works again.
What does status code 429 mean?
Servers, applications and interfaces limit how many requests a sender may make within a period of time. This protects against overload and against attacks such as trying out passwords en masse. If the limit is exceeded, the server responds with 429 - often together with the Retry-After header, which states when you can try again.
Typical causes
- Many login attempts in a short time - protection against password guessing
- Scripts, synchronisations or interface calls (APIs) without a pause between requests
- Aggressive bots and crawlers fetching very many pages at once
- Security or firewall plugins of your CMS with strict limits
- Limits of external services your website queries - such as payment, map or shipping services
Solution for visitors
- Wait a few minutes and then reload the page.
- Avoid reloading repeatedly in quick succession - every attempt counts.
- If the error persists, contact the operator of the website.
Solution for site operators
- Narrow down the source: the access log shows which IP addresses and addresses trigger the 429 responses (reading log files). If the limit comes from an external service, the error appears in its response or in your application's log.
- Throttle your own scripts: add pauses between requests, evaluate
Retry-Afterand retry failed requests with increasing intervals. - Use caching: cached responses save requests to interfaces and the database.
- Control bots: limit unwanted crawlers via
robots.txtor your security plugin. It is even more convenient with ShieldCache: bot management and rate limiting keep unwanted traffic away before it reaches your website - your real visitors remain unaffected. - Check plugin limits: if the values of your security plugin are too strict for your visitor numbers, adjust them moderately.
- Legitimate traffic slowed down? Get in touch - we will look into the situation together with you.
Related status codes
- 403 Forbidden - access denied, for example after an IP block
- 503 Service Unavailable - temporarily unavailable
- All status codes at a glance