What it means

Your client_id has burned through its per-minute or per-day budget. We return 429 until the sliding window opens back up.

Budgets

Both windows apply; the tighter remaining budget wins. Premium-tier partners can negotiate higher limits — talk to your DSS account contact.

Headers on every authenticated response

Every 200, 304, and 429 carries: 429 also includes Retry-After: <seconds>.

What to do

  1. Respect Retry-After. Wait at least that long before retrying.
  2. Back off, don’t retry tight. A retry loop that ignores Retry-After will keep hitting 429 for the rest of the window.
  3. Use conditional GETs. Pair every read with the prior ETag or Last-Modified — a 304 Not Modified counts as 1 request but returns no body. See Rate limits for the full polling story.
  4. Subscribe to webhooks. They cost zero rate-limit budget. Polling every user every minute will burn your budget fast; webhooks + a conditional GET on receipt is essentially free.