specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Open Food Facts providerId: open-food-facts created: '2026-05-04' generated: '2026-09-17' method: searched source: https://openfoodfacts.github.io/openfoodfacts-server/api/ modified: '2026-09-17' tags: - Rate Limiting - Quotas - Throttling description: >- Rate limits Open Food Facts publishes on its own API documentation. Limits are enforced per IP address, not per key — the project issues no API keys. Replaces the 2026-05-04 scaffold, whose tier/quota values were never published by the provider. headers: note: >- Open Food Facts does not document any RateLimit-* or X-RateLimit-* response headers, and none was observed on an unauthenticated read. An agent cannot read remaining quota from a response; it must respect the documented per-minute ceilings. limit: null remaining: null reset: null retryAfter: null policy: null responseCodes: throttled: 503 quotaExceeded: 503 limits: - name: Product read queries scope: ip metric: requests_per_minute limit: 15 timeFrame: minute applies: - Open Food Facts API v2 - Open Food Facts API v3 evidence: https://openfoodfacts.github.io/openfoodfacts-server/api/ quote: 15 req/min/IP address for all read product queries - name: Search queries scope: ip metric: requests_per_minute limit: 10 timeFrame: minute applies: - Open Food Facts API v2 - Search-a-licious API evidence: https://openfoodfacts.github.io/openfoodfacts-server/api/ quote: 10 req/min/IP address for all search queries - name: Global ceiling across all clients scope: global metric: requests limit: null timeFrame: null applies: - Open Food Facts API v2 - Open Food Facts API v3 evidence: https://openfoodfacts.github.io/openfoodfacts-server/api/ note: >- The documentation states a global rate limit exists across all IPs and that HTTP 503 is returned when it is exceeded, without publishing the numeric ceiling. identification: requirement: >- Every request must carry a custom User-Agent in the form "AppName/Version (ContactEmail)". The project states that unidentified clients generating problematic traffic may be blocked. This is the practical rate-limit key on a keyless API. See authentication/open-food-facts-authentication.yml.