specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: cdisc providerId: cdisc generated: '2026-09-17' method: probed source: >- live unauthenticated request to https://library.cdisc.org/api/mdr/products (401, headers captured 2026-09-17); https://www.cdisc.org/cdisc-library/api-documentation ; https://wiki.cdisc.org/display/LIBSUPRT/How-to+articles (403, Cloudflare bot challenge) created: '2026-05-04' modified: '2026-09-17' tags: - Rate Limiting - Quotas - Throttling limit_count: 0 description: >- No rate limit is published for the CDISC Library API, and none is signalled at runtime. A live request to https://library.cdisc.org/api/mdr/products returned 401 with Date, Content-Type, Content-Length, Connection, Request-Context and WWW-Authenticate — and no RateLimit-*, X-RateLimit-* or Retry-After header. The API documentation page carries no limits; the CDISC Library knowledge base, where an operational limit would most likely be stated, is behind a Cloudflare bot challenge and could not be read by a machine. The gateway is Azure API Management, which CAN enforce per-subscription quotas, so an undocumented limit may well exist — this records that a consumer has no published way to know it. headers: observed: [] documented: [] responseCodes: throttled: null note: 429 is not declared in any published CDISC contract. limits: [] observation: url: https://library.cdisc.org/api/mdr/products status: 401 probed: '2026-09-17' response_headers_seen: - Date - Content-Type - Content-Length - Connection - Request-Context - WWW-Authenticate note: >- This file replaces a 2026-05-04 bulk-sweep scaffold that asserted three tiers of limits (10 rpm free burst 20, and a monthly quota) and a full X-RateLimit-* header set. CDISC publishes none of that. The invented values are removed rather than kept alongside the finding.