specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Continuous Delivery Foundation providerId: continuous-delivery-foundation generated: '2026-09-05' created: '2026-05-04' modified: '2026-09-05' method: searched source: >- project documentation (docs.screwdriver.cd, spinnaker.io/docs, jenkins.io/doc), the four harvested OpenAPI contracts, and live response headers from https://api.screwdriver.cd/v4/ description: >- Published rate limits for the Continuous Delivery Foundation project APIs. There are none. REPLACES a scaffold written by the 2026-05-04 bulk sweep which asserted a free/professional/ enterprise tier ladder with 10/100/1000 requests per minute and X-RateLimit-* response headers. None of that was published by anyone — the CDF ships self-hosted open source, so quotas are set by whoever runs the instance, not by the project. limit_count: 0 limits: [] headers: request: - name: X-RateLimit-App projects: [Spinnaker] required: false operations: 47 note: >- The one rate-limit-shaped thing in any published contract, and it points the wrong way: it is an optional REQUEST header by which a caller labels itself so that an operator's own rate-limiting can attribute the call. It is not a limit and it is not a signal back. response: [] responseCodes: {} findings: - project: Screwdriver documented_limits: false observed_headers: [] evidence: >- GET https://api.screwdriver.cd/v4/openapi.json returns no X-RateLimit-*, RateLimit-* or Retry-After header (response headers observed 2026-09-05: date, content-type, content-length, vary, cache-control, set-cookie, strict-transport-security). - project: Spinnaker documented_limits: false evidence: >- https://spinnaker.io/docs/guides/operator/rate-limiting/ returns 404; the Gate contract declares no 429 response on any of its 288 operations. - project: Jenkins documented_limits: false evidence: >- Self-hosted controller; throttling is a plugin/operator concern, not a published API limit. - project: JayeX documented_limits: false - project: Ortelius documented_limits: false - project: CDEvents documented_limits: false note: a specification, not a callable service — rate limits are not applicable note: >- An honest zero. Every CDF API surface is software the consumer runs themselves, so no rate limit exists to publish. The single exception worth watching is api.screwdriver.cd, a project-operated cluster that could impose one and currently signals none. maintainers: - FN: Kin Lane email: kin@apievangelist.com