Limits are approximate. Treat the headers as guidance, not an exact count.
Headers
Every response from an authenticated call carries:RateLimit-Reset is the number of seconds until the current window resets. These headers are set on every response, not only on a rejected one. Use them to back off before you are throttled.
A rejected request also carries:
When you are throttled
Both carry
retry_after_seconds in the error body, matching the Retry-After header.
Retrying
ReadRetry-After or retry_after_seconds, and wait at least that long before your next call. A script that retries on its own should back off with jitter, not retry at a fixed interval. Retries that all arrive the moment the window resets get throttled again.
Writes have a smaller budget than reads. It stops a runaway script from filing many requests or declines before anyone notices. Build polling around the per-minute limit. Keep the write budget for occasional changes.
Related
Idempotency
Safe retries for writes, independent of rate limiting.
Errors
Every error code this API returns.