specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Defense Health Agency providerId: defense-health-agency created: '2026-05-04' modified: '2026-09-07' generated: '2026-09-07' method: searched source: https://www.health.mil/Military-Health-Topics/Technology/MHS-GENESIS tags: - Federal Government - Defense - Department of Defense - Health - Military Health System - MHS Genesis - FHIR - Health IT - Rate Limiting description: >- The Defense Health Agency documents no API rate limits, quotas, throttling behaviour or rate-limit response headers. There is no public developer documentation on any DHA host in which such limits could be stated, and no public endpoint against which they could be observed. limit_count is 0 and that is an honest measurement. limit_count: 0 limits: [] headers: {} responseCodes: {} policies: [] observed: note: >- No limits were observed live either: DHA exposes no unauthenticated API endpoint. health.mil, dha.mil and tricare.mil sit behind an F5 TSPD bot-defense interstitial that answers command-line clients with a JavaScript challenge, so even the public web tier cannot be used to observe RateLimit-* headers. supersedes: note: >- This file replaces a 2026-05-04 bulk-sweep scaffold that asserted X-RateLimit-Limit / -Remaining / -Reset and RateLimit-Policy response headers, a 429 throttle code, and free/professional/enterprise limits of 10/100/1000 requests per minute against the "MHS Genesis SMART on FHIR API". DHA publishes none of that; it was template default content. Removed 2026-09-07 under the no-fabrication rule. maintainers: - FN: Kin Lane email: kin@apievangelist.com