Skip to content
Detection & blocking

What is Rate Limiting?

Restricting how many requests a client may send within a time window, after which further requests are delayed, challenged or blocked.

A rate limit counts requests per client — usually per IP address, but also per session cookie, API key, ASN or TLS fingerprint — and acts once a threshold is crossed within a period. The standard response is HTTP 429 Too Many Requests, often with a Retry-After header saying how long to wait.

Spreading requests across rotating proxies raises the rate you can sustain only when the limit is counted per IP. When it counts by something you carry across exits, such as a cookie or a client fingerprint, a new IP inherits the same counter.

The durable approach is to measure the threshold, run well below it, add jitter, and honour Retry-After rather than retrying immediately.