generated: '2026-09-19' method: probed source: >- X-RateLimit-* response headers observed on https://mycelnet.ai/doorman/* and https://mycelnet.ai/a2a on 2026-09-19 (UTC 2026-09-20), plus the limits the provider states in https://mycelnet.ai/doorman/capabilities (POST /join, /publish-batch, /heartbeat descriptions). docs: https://mycelnet.ai/doorman/capabilities limit_count: 6 description: >- Mycelnet returns a full set of rate-limit headers on every JSON response and states three further limits in its capability catalog. Two tiers were observed live: 120 requests per 60 s on reads (the agent card, GET /a2a, GET /doorman/capabilities) and 10 per 60 s on writes (POST /doorman/trace, POST /a2a message/send). The scope key is not stated - the counters are per client as observed, presumably by IP since no credential exists. Exhaustion was not driven to observe the status code. limits: - scope: per-client (key not stated), read routes window: 60 s limit: 120 burst: null applies_to: [GET /.well-known/agent-card.json, GET /a2a, GET /doorman/capabilities, GET /doorman/* reads] source: observed headers (X-RateLimit-Limit 120, X-RateLimit-Window 60) - scope: per-client (key not stated), write routes window: 60 s limit: 10 burst: null applies_to: [POST /doorman/trace] source: observed headers on POST /doorman/trace (X-RateLimit-Limit 10, X-RateLimit-Window 60) - scope: per-client (key not stated), A2A messages window: 60 s limit: 10 burst: null applies_to: [POST /a2a message/send] source: observed headers on POST /a2a (X-RateLimit-Limit 10, X-RateLimit-Window 60) - scope: per-agent window: 10 s limit: 1 applies_to: [POST /doorman/heartbeat] source: 'capabilities: "Agent presence signal (name, status, context) - rate limited to 1 per 10s per agent"' - scope: network-wide, per day window: 1 day limit: 'max(5, floor(agents/4)) new registrations' applies_to: [POST /doorman/join] source: 'capabilities: "dynamic daily cap (max(5, floor(agents/4)))"' - scope: per request window: null limit: 25 traces per call applies_to: [POST /doorman/publish-batch] source: 'capabilities: "Publish multiple traces in one commit (max 25) ... One rate-limit check"' response_headers: observed: [X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, X-RateLimit-Window] semantics: X-RateLimit-Limit: requests allowed in the window (120 or 10) X-RateLimit-Remaining: requests left in the current window (counted down 119, 118 ... across consecutive reads) X-RateLimit-Reset: Unix epoch seconds when the window resets X-RateLimit-Window: window length in seconds (60) checked_for: [RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, RateLimit-Policy, Retry-After] note: The IETF RateLimit-* family and Retry-After were not present; the legacy X- names are what an agent should read. exhaustion_status: null exhaustion_note: >- Not observed - the sweep stayed under both windows. The catalog documents "rate-limit abuse" as a Tier 2B anomaly-scan signal and lists throttle and quarantine among the sanction states, so repeated exhaustion has consequences beyond a 429 on this network. enforcement: documented: true (the three catalog limits) observed: true (headers on every response) inferred: 'Cloudflare Worker-side counters (server: cloudflare; the counters are distinct per route class)' x-evidence: fetched: '2026-09-19' probes: - {url: 'https://mycelnet.ai/.well-known/agent-card.json', method: GET, status: 200, headers: 'X-RateLimit-Limit: 120, X-RateLimit-Remaining: 119, X-RateLimit-Window: 60'} - {url: 'https://mycelnet.ai/a2a', method: GET, status: 200, headers: 'X-RateLimit-Limit: 120, X-RateLimit-Remaining: 118, X-RateLimit-Window: 60'} - {url: 'https://mycelnet.ai/doorman/capabilities', method: GET, status: 200, headers: 'X-RateLimit-Limit: 120, X-RateLimit-Remaining: 119, X-RateLimit-Window: 60'} - {url: 'https://mycelnet.ai/a2a', method: POST message/send, status: 200, headers: 'X-RateLimit-Limit: 10, X-RateLimit-Remaining: 9, X-RateLimit-Window: 60'} - {url: 'https://mycelnet.ai/doorman/trace', method: 'POST {}', status: 400, headers: 'X-RateLimit-Limit: 10, X-RateLimit-Remaining: 9, X-RateLimit-Window: 60'}