ErrorCS2 API errors

Steam API 429 Too Many Requests: the fix.

A 429 from api.steampowered.com means Steam is rate limiting your key or IP. Stop, wait with exponential backoff and random jitter, then retry a limited number of times. Retrying immediately extends the block. Then cut call volume so it stops happening.

  • Rate limited
  • Exponential backoff + jitter
  • No documented Retry-After
GET /cs2/matches/upcoming?limit=2200 OK
$ curl "https://api.citoapi.com/api/v1/cs2/matches/upcoming?limit=2" \ -H "x-api-key: $CITO_API_KEY"
{  "success": true,  "data": [    {      "id": "cs2-match-2398594",      "eventName": "CCT 2026 South America Series 6",      "startsAt": "2026-10-03T22:00:00.000Z",      "team1Name": "ex-Keyd Stars",      "team2Name": "Procyon"    },    {      "id": "cs2-match-2398853",      "eventName": "ESN Fall Showdown 2026",      "startsAt": "2026-10-04T06:00:00.000Z",      "team1Name": "The Huns",      "team2Name": "5star"    }    ...  ]}

The error

What you see
HTTP/1.1 429 Too Many Requests
Server: nginx
(response from api.steampowered.com)

What does a Steam 429 mean?

Valve's response-code list defines 429 as the caller being rate limited. It is temporary: the same request succeeds later. It is different from 403, which means the request will never succeed as sent.

Why am I getting 429s?

You are sending more calls than Steam accepts from your key or IP: over the 100,000-a-day key limit, too many in a short burst, or from an IP Steam has flagged because it keeps producing 403s. Shared hosting and serverless platforms can also share an outbound IP with other heavy callers.

How do I retry correctly?

Retry only 429 and 5xx responses, wait 1, 2, 4, 8 seconds and so on with random jitter, cap the wait and the number of tries, and honour Retry-After if a response ever carries one.

Python: retry with exponential backoff and jitter
import random, time, requests

def get_with_backoff(url, params, tries=6, cap=60):
    for attempt in range(tries):
        r = requests.get(url, params=params, timeout=10)
        if r.status_code not in (429, 500, 502, 503, 504):
            return r
        retry_after = r.headers.get("Retry-After")
        wait = float(retry_after) if retry_after else min(cap, 2 ** attempt) + random.uniform(0, 1)
        time.sleep(wait)
    return r  # still failing: surface it, do not loop forever
Node.js 18+
async function getWithBackoff(url, tries = 6, cap = 60_000) {
  let res
  for (let attempt = 0; attempt < tries; attempt++) {
    res = await fetch(url)
    if (![429, 500, 502, 503, 504].includes(res.status)) return res
    const ra = Number(res.headers.get("retry-after"))
    const wait = ra > 0 ? ra * 1000 : Math.min(cap, 2 ** attempt * 1000) + Math.random() * 1000
    await new Promise((r) => setTimeout(r, wait))
  }
  return res
}

How do I stop triggering it?

Backoff only makes 429s survivable; fewer calls make them rare. Cache responses, batch Steam IDs, poll less often, and fix whatever produces 403s, since that traffic is limited more strictly.

How does the CS2 API make Steam 429s impossible?

Pro CS2 data never touches Steam, so there is no Steam rate limit to hit. The CS2 API has its own published limits, and unlike Steam it tells you how long to wait: every CS2 API 429 carries Retry-After, X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset, so the backoff code above waits exactly the right time.

Frequently asked questions

Something missing? Email support@citoapi.com.

How long does a Steam 429 last?

Valve does not publish it. Back off exponentially from one second up to about a minute, and if 429s continue for hours you are over the 100,000-calls-a-day key limit.

Is a 429 the same as a ban?

No. 429 is a temporary rate limit. A request that can never succeed returns 403.

Should I rotate Steam API keys to avoid 429s?

Valve's terms limit calls per key and require keys to be kept confidential; rotating keys to dodge limits is not a fix. Reduce calls instead.

See pricing

Build CS2 live score apps

Free is for building and testing. Paid plans add commercial use, real-time live data and the full archive.