Re: New global API rate limits deployed for anonymous requests
Daniel Kinzler via Wikitech-l <[email protected]> Mon, 16 Mar 2026 14:54:40 +0100
| Newsgroups | gmane.science.linguistics.wikipedia.technical |
|---|---|
| Organization | Wikimedia Foundation |
| Message-ID | <[email protected]> |
Am 16.03.26 um 12:07 schrieb Travis Briggs via Wikitech-l: > Great idea, I think Referer is completely reasonable as a rate limiting > signal, because it is no worse than User-Agent from a spoofing/abuse perspective. Because the User-Agent is spoofable, we will likely stop using it as a rate limit key soon-ish for requests coming from outside WMCS. Sending a compliant user-Agent will give you a better rate limit than not doing so, but not a *great* limit. So adding more untrusted headers into the mix is not going to help In the long run, authenticating, or asking users to authenticate, will be the only way for apps and bots to ensure virtually unlimited API access. Unauthenticated traffic will generally be rate limited per IP. -- Daniel Kinzler Principal Software Engineer MediaWiki Engineering Group Wikimedia Foundation _______________________________________________ Wikitech-l mailing list -- [email protected] To unsubscribe send an email to [email protected] https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/