Re: New global API rate limits deployed for anonymous requests

Daniel Kinzler via Wikitech-l <[email protected]> Mon, 16 Mar 2026 16:48:40 +0100
Newsgroups gmane.science.linguistics.wikipedia.technical
Organization Wikimedia Foundation
Message-ID <[email protected]>
Hi Travis!

Yes, we are trying to avoid disrupting community tools. This is why we are not 
rate limiting requests from WMCS for now, and if we do limit them, the limits 
are going to be fairly high. So tools on Toolforge and the wider WMCS should be 
safe.

Beyond that, we are doing the preliminary per-user-agent limits precisely to 
give people time to adjust, and allow us to see which 
unauthenticated-but-compliant bots are hitting limits.

Another thing we are doing is using heuristics to distinguish bots from browser 
based requests. I don't know the specifics of that "secret sauce", but I expect 
the referrer header goes into it somehow.

In general, we don't want to get in the way of the community doing their thing. 
But if we make it easy to bypass the rate limits, the "wrong" people will start 
doing that sooner or later. At that point, we'll have to clamp down, and that 
would break community tools. It's better to nudge people to start authenticating 
before that happens... but in my experience, people don't change their code 
until it breaks... It's tricky to do this nicely, and at the same time, in a 
timely manner, before it gets so urgent that we have to act quickly.

-- 
Daniel Kinzler
Principal Software Engineer
MediaWiki Engineering Group
Wikimedia Foundation

_______________________________________________
Wikitech-l mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/