--- title: "1.32.1 — Exempt throttle paths no longer count against an identity" description: "A request on a path listed in API_THROTTLE_EXEMPT_PREFIXES was never refused, but it still counted toward the caller's global throttle budget, so a burst of exempt traffic could 429 the caller's next ordinary request. Exempt requests no longer count against the identity. Traffic totals and top-talke…" date: "2026-10-03" tags: ["release"] canonical: "https://django-mojo.sitesmojo.com/changelog/1-32-1/" --- A request on a path listed in API_THROTTLE_EXEMPT_PREFIXES was never refused, but it still counted toward the caller's global throttle budget, so a burst of exempt traffic could 429 the caller's next ordinary request. Exempt requests no longer count against the identity. Traffic totals and top-talker lists still see them. ### Changed - A request on an exempt prefix no longer increments the identity's global throttle counter. It is still counted in the traffic bucket totals and in the top-talker and top-IP sets, so traffic concentration detection is unchanged. - An exempt request neither counts toward nor triggers an API key's observation threshold. A key that mixes exempt and ordinary traffic reaches the threshold on its ordinary requests only. ### Upgrade notes - Only projects that set `API_THROTTLE_EXEMPT_PREFIXES` are affected. The default is an empty list, and a project that has not set it behaves exactly as before. - An exempt path is no longer bounded by the global throttle in any way. A project that exempts a path should bound it some other way, for example a per-address limit.