Re: New global API rate limits deployed for anonymous requests

Daniel Kinzler via Wikitech-l <[email protected]> Mon, 16 Mar 2026 14:54:40 +0100
Newsgroups gmane.science.linguistics.wikipedia.technical
Organization Wikimedia Foundation
Message-ID <[email protected]>
Am 16.03.26 um 12:07 schrieb Travis Briggs via Wikitech-l:
> Great idea, I think Referer is completely reasonable as a rate limiting 
> signal, because it is no worse than User-Agent from a spoofing/abuse perspective.

Because the User-Agent is spoofable, we will likely stop using it as a rate 
limit key soon-ish for requests coming from outside WMCS. Sending a compliant 
user-Agent will give you a better rate limit than not doing so, but not a 
*great* limit. So adding more untrusted headers into the mix is not going to help

In the long run, authenticating, or asking users to authenticate, will be the 
only way for apps and bots to ensure virtually unlimited API access. 
Unauthenticated traffic will generally be rate limited per IP.

-- 
Daniel Kinzler
Principal Software Engineer
MediaWiki Engineering Group
Wikimedia Foundation

_______________________________________________
Wikitech-l mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/