1.32.1 — Exempt throttle paths no longer count against an identity
Editorial identity incomplete
2026-10-03
A request on a path listed in API_THROTTLE_EXEMPT_PREFIXES was never refused, but it still counted toward the caller's global throttle budget, so a burst of exempt traffic could 429 the caller's next ordinary request. Exempt requests no longer count against the identity. Traffic totals and top-talker lists still see them.
Changed
- A request on an exempt prefix no longer increments the identity's global throttle counter. It is still counted in the traffic bucket totals and in the top-talker and top-IP sets, so traffic concentration detection is unchanged.
- An exempt request neither counts toward nor triggers an API key's observation threshold. A key that mixes exempt and ordinary traffic reaches the threshold on its ordinary requests only.
Upgrade notes
- Only projects that set
API_THROTTLE_EXEMPT_PREFIXESare affected. The default is an empty list, and a project that has not set it behaves exactly as before. - An exempt path is no longer bounded by the global throttle in any way. A project that exempts a path should bound it some other way, for example a per-address limit.