Agent skill

API Rate Limit Handler

by sickn33 in sickn33/agentic-awesome-skills

Implement bounded, idempotency-aware API throttling, backoff, and retry handling for 429 and transient 5xx responses.

MITAuto-check passedBackend & APIs

Install API Rate Limit Handler

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill api-rate-limit-handler -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills api-rate-limit-handler --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-rate-limit-handler .claude/skills/api-rate-limit-handler && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-rate-limit-handler
GitHub stars
47k
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
588 words
Files
1
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Implement bounded, idempotency-aware API throttling, backoff, and retry handling for 429 and transient 5xx responses.

  • Works in 4 steps: Classify the response → Parse rate limit headers → Implement the retry loop → …
  • Tasks that involve Rate limiting
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Examples, plus 4 more sections
  • Reaches api.github.com

What it does

API Rate Limit Handler is an agent skill from sickn33/agentic-awesome-skills. Implement bounded, idempotency-aware API throttling, backoff, and retry handling for 429 and transient 5xx responses.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Rate limiting. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Rate limiting

Example prompts

  • “/api-rate-limit-handler”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Classify the response
  2. Parse rate limit headers
  3. Implement the retry loop
  4. Add a client-side rate limiter (proactive)

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Rate Limit Handler loads about 2.4k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 588 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 588 words, ~2,429 tokens.

Download SKILL.mdSave it as .claude/skills/api-rate-limit-handler/SKILL.md (or your agent's skills folder).
name
api-rate-limit-handler
description
Implement bounded, idempotency-aware API throttling, backoff, and retry handling for 429 and transient 5xx responses.
category
development
risk
safe
source
self
source_type
self
date_added
2026-08-26
author
Prajeeth-12
tags
rate-limiting, retry, backoff, api, resilience, throttle, 429
tools
claude, cursor, codex, gemini
license
MIT

API Rate Limit Handler

Overview

A skill for implementing production-grade rate limiting, exponential backoff, and retry strategies when integrating with external APIs. Prevents cascading failures, respects upstream quotas, and keeps your application resilient under load.

When to Use This Skill

  • Use when calling external APIs that enforce rate limits (OpenAI, Stripe, GitHub, etc.)
  • Use when you receive 429 Too Many Requests or 5xx errors and need graceful recovery
  • Use when building a client that must respect Retry-After headers
  • Use when designing a system that fans out to multiple API providers
  • Use when the user says "handle rate limits", "add retry logic", "backoff strategy", or "don't get throttled"

How It Works

Step 1: Classify the response

Determine whether a failed request is retryable or terminal.

StatusClassificationAction
200-299SuccessReturn response
400, 401, 403, 404Terminal client errorDo not retry — fix the request
408, 429Retryable (rate limit / timeout)Retry with backoff
500, 502, 503, 504Retryable (server error)Retry with backoff
Step 2: Parse rate limit headers

Always check upstream hints before computing your own delay.

typescript
function getRetryDelay(
  response: Response,
  attempt: number,
  maxDelayMs = 60_000
): number {
  // Prefer upstream hints
  const retryAfter = response.headers.get("Retry-After");
  if (retryAfter) {
    const seconds = Number(retryAfter);
    if (Number.isFinite(seconds) && seconds >= 0) {
      return Math.min(seconds * 1000, maxDelayMs);
    }
    // HTTP-date format
    const date = new Date(retryAfter).getTime();
    if (Number.isFinite(date)) {
      return Math.min(Math.max(0, date - Date.now()), maxDelayMs);
    }
  }

  // GitHub documents x-ratelimit-reset as Unix epoch seconds.
  const githubReset = Number(response.headers.get("x-ratelimit-reset"));
  if (Number.isFinite(githubReset)) {
    return Math.min(
      Math.max(0, githubReset * 1000 - Date.now()),
      maxDelayMs
    );
  }

  // Fallback: capped exponential backoff with full jitter.
  const cap = Math.min(1000 * 2 ** attempt, maxDelayMs);
  return Math.floor(Math.random() * cap);
}

Provider-specific reset headers do not share one unit or format. For example, some APIs return durations while GitHub returns epoch seconds. Parse an additional header only after checking that provider's current documentation.

Step 3: Implement the retry loop
typescript
async function fetchWithRetry(
  url: string,
  options: RequestInit,
  maxRetries = 3,
  maxElapsedMs = 120_000,
  retryNonIdempotent = false
): Promise<Response> {
  const startedAt = Date.now();
  const method = (options.method ?? "GET").toUpperCase();
  const replaySafe = ["GET", "HEAD", "OPTIONS", "PUT", "DELETE"].includes(method)
    || retryNonIdempotent;

  for (let attempt = 0; attempt <= maxRetries; attempt++) {
    const response = await fetch(url, options);

    if (response.ok) return response;

    // Terminal errors — do not retry
    if ([400, 401, 403, 404, 422].includes(response.status)) {
      throw new Error(`Terminal error ${response.status}: ${response.statusText}`);
    }

    if (!replaySafe) {
      throw new Error(
        `${method} was not retried because replay safety was not explicitly established`
      );
    }

    // Retryable — but exhausted attempts
    if (attempt === maxRetries) {
      throw new Error(`Failed after ${maxRetries} retries: ${response.status}`);
    }

    const remaining = maxElapsedMs - (Date.now() - startedAt);
    const delay = Math.min(getRetryDelay(response, attempt), remaining);
    if (delay <= 0) {
      throw new Error(`Retry deadline exceeded after ${maxElapsedMs}ms`);
    }

    // Release the connection before waiting when the body is not needed.
    await response.body?.cancel();
    console.warn(
      `Request failed (${response.status}), retrying in ${Math.round(delay)}ms (attempt ${attempt + 1}/${maxRetries})`
    );
    await new Promise(resolve => setTimeout(resolve, delay));
  }

  throw new Error("Unreachable");
}
Step 4: Add a client-side rate limiter (proactive)

Prevent hitting upstream limits in the first place with a token bucket or sliding window.

typescript
class TokenBucket {
  private tokens: number;
  private lastRefill: number;
  private queue: Promise<void> = Promise.resolve();

  constructor(
    private maxTokens: number,
    private refillRate: number // tokens per second
  ) {
    this.tokens = maxTokens;
    this.lastRefill = Date.now();
  }

  async acquire(): Promise<void> {
    const ticket = this.queue.then(() => this.acquireOnce());
    this.queue = ticket.catch(() => undefined);
    return ticket;
  }

  private async acquireOnce(): Promise<void> {
    this.refill();
    if (this.tokens < 1) {
      const waitMs = ((1 - this.tokens) / this.refillRate) * 1000;
      await new Promise(resolve => setTimeout(resolve, waitMs));
      this.refill();
    }
    this.tokens -= 1;
  }

  private refill(): void {
    const now = Date.now();
    const elapsed = (now - this.lastRefill) / 1000;
    this.tokens = Math.min(this.maxTokens, this.tokens + elapsed * this.refillRate);
    this.lastRefill = now;
  }
}

// Usage: limit to 60 requests/minute
const limiter = new TokenBucket(60, 1);

async function rateLimitedFetch(url: string, options: RequestInit) {
  await limiter.acquire();
  return fetchWithRetry(url, options);
}

Examples

Example 1: Idempotent API read with retry
typescript
const response = await fetchWithRetry(
  "https://api.github.com/repos/OWNER/REPO",
  {
    method: "GET",
    headers: {
      "Accept": "application/vnd.github+json",
      "Authorization": `Bearer ${githubToken}`,
    },
  },
  3
);

For a POST or another operation with side effects, leave retryNonIdempotent false unless the provider documents an idempotency mechanism and the same stable idempotency key is reused for every attempt.

Example 2: Python implementation
python
import time
import random
import httpx

def fetch_with_retry(url: str, max_retries: int = 3, **kwargs) -> httpx.Response:
    for attempt in range(max_retries + 1):
        response = httpx.request("GET", url, **kwargs)

        if response.is_success:
            return response

        if response.status_code in (400, 401, 403, 404, 422):
            response.raise_for_status()

        if attempt == max_retries:
            response.raise_for_status()

        # Parse Retry-After or compute backoff
        retry_after = response.headers.get("retry-after")
        if retry_after and retry_after.isdigit():
            delay = int(retry_after)
        else:
            delay = min(2 ** attempt + random.uniform(0, 1), 60)

        print(f"Retrying in {delay:.1f}s (attempt {attempt + 1}/{max_retries})")
        time.sleep(delay)

    raise RuntimeError("Unreachable")

Best Practices

  • ✅ Always respect Retry-After headers — they come from the provider who knows their limits
  • ✅ Add jitter to backoff to prevent thundering herd when multiple clients retry simultaneously
  • ✅ Log every retry with status code, delay, and attempt number for debugging
  • ✅ Set a maximum total timeout to avoid hanging indefinitely
  • ✅ Use a client-side rate limiter proactively rather than only reacting to 429s
  • ✅ Retry state-changing requests only with a provider-documented idempotency mechanism and a stable key
  • ❌ Don't retry 4xx client errors (except 408 and 429) — fix the request instead
  • ❌ Don't use fixed delays — exponential backoff distributes load more evenly
  • ❌ Don't retry without a cap — unbounded retries can amplify outages
  • ❌ Don't ignore per-endpoint limits — some APIs have different quotas per route
Show full SKILL.md (189 more words)Show less

Limitations

  • This skill does not replace environment-specific validation, testing, or expert review.
  • Token bucket is approximate for distributed systems — use Redis-backed rate limiting for multi-instance deployments (for example the upstash-ratelimit skill, or any shared-store limiter).
  • Some APIs use non-standard rate limit headers; check provider documentation.
  • The elapsed-time cap shown here bounds retry waits, not a single hung network call; combine it with an AbortSignal or client timeout.

Common Pitfalls

  • Problem: Retrying too aggressively during an outage amplifies the problem. Solution: Use exponential backoff with jitter and a circuit breaker for sustained failures.

  • Problem: Multiple instances of your app all retry at the same time (thundering herd). Solution: Add randomized jitter (Math.random() * 0.3 * delay) to decorrelate retries.

  • Problem: Retry-After header contains an HTTP-date instead of seconds. Solution: Parse both formats — check if the value is numeric first, then try Date parsing.

  • Problem: Client-side limiter doesn't account for concurrent requests already in-flight. Solution: Serialize acquisition within one process, decrement before send, and use a shared distributed limiter across instances.

  • @poka-yoke - Mistake-proofing APIs so invalid requests never reach the retry path
  • @circuit-breaker - When to stop retrying entirely and fail fast

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/api-rate-limit-handler of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1e53ce2

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

API Rate Limit Handler next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Rate Limit Handler compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Rate Limit Handler this skillsickn33/agentic-awesome-skills47k1 repos~2.4kAutomated safety check: PassMIT
Upstash Ratelimit TSupstash/ratelimit-js2.1k1 repos~313Automated safety check: PassMIT
API Gatewayitsmostafa/aws-agent-skills1.2k1 repos~2.2kAutomated safety check: PassMIT
Add Hosted Keysimstudioai/sim30k—~3.4kAutomated safety check: PassApache-2.0
Repo2skillzhangyanxs/repo2skill246—~3.6kAutomated safety check: PassNone
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence

Similar skills

  • Upstash Ratelimit TS

    upstash/ratelimit-js

    Official

    Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.

    2.1k GitHub starsUsed in 1 repo~313 tokens
    Backend & APIsAuto-check passed
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Backend & APIsAuto-check passed
  • Add Hosted Key

    simstudioai/sim

    Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.

    30k GitHub stars~3.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Repo2skill

    zhangyanxs/repo2skill

    Convert GitHub/GitLab/Gitee repositories into comprehensive OpenCode Skills using embedded LLM calls with multiple mirrors and rate limit handling

    246 GitHub stars~3.6k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated today
    Backend & APIsAuto-check passed
  • Dload Fetch Tool

    php-internal/dload

    Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).

    105 GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about API Rate Limit Handler

What does API Rate Limit Handler do?

Implement bounded, idempotency-aware API throttling, backoff, and retry handling for 429 and transient 5xx responses. API Rate Limit Handler is an agent skill from sickn33/agentic-awesome-skills. Implement bounded, idempotency-aware API throttling, backoff, and retry handling for 429 and transient 5xx responses.

When should I use API Rate Limit Handler?

API Rate Limit Handler fits situations like: tasks that involve Rate limiting.

How do I install API Rate Limit Handler in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill api-rate-limit-handler -a claude-code`. Or copy the skill folder (skills/api-rate-limit-handler in sickn33/agentic-awesome-skills) into .claude/skills/api-rate-limit-handler in your project. Claude Code loads it when a task matches its description.

How do I install API Rate Limit Handler in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill api-rate-limit-handler -a codex`. Or copy the skill folder (skills/api-rate-limit-handler in sickn33/agentic-awesome-skills) into .agents/skills/api-rate-limit-handler in your project. Codex loads it when a task matches its description.

Can I use API Rate Limit Handler in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill api-rate-limit-handler -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-rate-limit-handler, .gemini/skills/api-rate-limit-handler, .github/skills/api-rate-limit-handler and .opencode/skills/api-rate-limit-handler in your project.

What does API Rate Limit Handler need to run?

SKILL.md names no scripts, command-line tools or credentials: API Rate Limit Handler is instructions for the agent only. Our summary lists: Python 3.

Does API Rate Limit Handler access the network?

SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is API Rate Limit Handler safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Rate Limit Handler use?

API Rate Limit Handler is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Rate Limit Handler use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Rate Limit Handler?

Skills that share tags, products or a category with API Rate Limit Handler: Upstash Ratelimit TS (upstash/ratelimit-js, 2.1k stars), API Gateway (itsmostafa/aws-agent-skills, 1.2k stars), Add Hosted Key (simstudioai/sim, 30k stars) and Repo2skill (zhangyanxs/repo2skill, 246 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Rate Limit Handler?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.