Used to just copy example headers and hope for the best. Then one morning our Stripe webhooks hit 429s at 9am in San Francisco and payments froze. That pushed me to actually read the Retry-After header and build a proper backoff. Now I check every vendor's limit policy before I write a single call. Has anyone else gotten burned by a hidden rate limit in production?