Figma's REST rate limits are tiered, not flat. Tier 1 (files, nodes, images) is the tightest at roughly 15 requests per minute on Professional; components, styles, metadata, and /v1/me are much looser. On a 429, honor the Retry-After header; for severe violations it can be multi-day, so back off instead of hammering. The limit follows the plan containing the file, so a paid seat elsewhere does not raise the quota on a Starter file. Practical defenses: narrow reads with ids and depth params instead of full-file pulls, cache component and style metadata, and never treat the REST API as a way around Figma quotas.

Context: Web (pi-stef figma package README): documents the Figma rate-limit gotchas that surprise agents: limits are tiered by endpoint, the 429 response carries a Retry-After header that can be multi-day for severe violations, and the limit follows the plan of the file you are reading, not your own seat.