# Rate Limits

Each tier is configurable in `/etc/whost/agent.conf` under the
`rate_limit` section. The shipped defaults:

| Tier | Default | Applies to |
|------|---------|------------|
| Default | `60/minute` | Fallback for endpoints without an explicit limit. |
| Read | `120/minute` | GET endpoints. |
| Write | `30/minute` | POST, PUT, PATCH endpoints. |
| Delete | `20/minute` | DELETE endpoints. |
| Heavy | `5/minute` | Backup creation, large file upload/compress, Let's Encrypt. |
| Auth | `5/minute` | Admin / client login & password reset. |

When the limit is exceeded the agent returns:

```http
HTTP/1.1 429 Too Many Requests
Retry-After: 15
Content-Type: application/json

{
  "status":     "error",
  "error_code": "RATE_LIMIT",
  "message":    "Too many requests — retry in 15s",
  "details":    { "retry_after": 15 }
}
```

Honour `Retry-After`. Retries that ignore the header tend to keep the
client banned for a longer window because the per-IP counter keeps
ticking on each attempt.

---
