Haven't had a chance to have more than a very brief look so far; and I don't have any apps in mind just yet. But:
1) massive thumbs up for good use of HATEOS :-) Too many people miss it, and it makes writing clients much easier in my experience (also makes your job much easier in maintaining the API)
2) there's a couple of namespace conflicts which make me itch, but I don't know how important they are in practice. In particular:
http://api.mixcloud.com/spartacus/
http://api.mixcloud.com/popular/
http://api.mixcloud.com/new/
http://api.mixcloud.com/me/
at first glance, I would think that the latter URLS refer to users whose usernames are "popular", "new", and "me". If the endpoints look exactly the same, that's probably ok, but it's still a bit odd. If I'm writing an app which says "enter a username here", I have to remember that these are not valid usernames; and I can imagine similar sort of special-casing might have to be put in elsewhere.
3) I still hate OAuth - it's probably still the best of a bad bunch, though! Nice overview of how to use it in practice.
4) minor issue - for exceeding rate limits, I'd use a 403 code not a 503. 5xx limits boil down to "it's the server's fault". 4xx are "it's your fault" and in this case I think the semantics are more user error than server error.