specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: drupal providerId: drupal created: '2026-05-04' modified: '2026-09-17' generated: '2026-09-17' method: searched source: https://www.drupal.org/drupalorg/docs/api tags: - Rate Limiting - Quotas - Throttling description: Real published limits for the Drupal surfaces. This file replaces a 2026-05-04 bulk-sweep scaffold that asserted X-RateLimit-* headers Drupal does not send. limit_count: 2 headers: limit: null remaining: null reset: null retry_after: null note: 'No rate-limit response headers are published or observed on any Drupal surface. GET https://www.drupal.org/api-d7/node.json returned content-type, cache-control: public, max-age=900 and x-drupal-cache only — no RateLimit-*, X-RateLimit-* or Retry-After. Probed 2026-09-17.' limits: - scope: per-request surface: https://www.drupal.org/api-d7 (Drupal.org REST API) window: per request limit: 50 unit: records detail: '"There is a hard-coded limit of 50 records per request." Query endpoints return up to 100 resources, paged.' source: https://www.drupal.org/drupalorg/docs/api method: searched - scope: per-client surface: https://www.drupal.org/api-d7 (Drupal.org REST API) window: ongoing limit: null unit: concurrency detail: 'Published as prose conditions of use rather than a number: send a descriptive User-Agent, make requests from a single thread, cache results locally where possible. "Abuse will be blocked as needed." There is no documented numeric request-per-second ceiling.' source: https://www.drupal.org/drupalorg/docs/api method: searched self_hosted_surfaces: applies_to: - /jsonapi - /?_format=json - /graphql - /_mcp limit: null note: Drupal core ships no rate limiter. Every limit on an installed site is set by the operator’s reverse proxy, CDN or WAF, so no limit can be published for the software itself. This is an honest absence, not an unmeasured one. exhaustion: status_code: null note: No documented exhaustion status. The Drupal.org API says abusive clients are blocked, without naming a response code.