Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

On October 19, your unauthenticated GitLab automation gets 60 requests an hour

Blog post from WorkOS

Post Details
Company
Date Published
Author
Maria Paktiti
Word Count
2,153
Company Posts That Month
44
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab.com will introduce subscription-tier-based rate limits on October 19, 2026 for Free users and unauthenticated traffic, followed by Premium and Ultimate customers in January 2027, with trial enforcement windows on October 7 and 14 intended to help users test automation. Unauthenticated requests will be restricted to 60 per hour per IP address, while authenticated users will receive hourly limits of 5,000, 15,000, or 25,000 requests for Free, Premium, and Ultimate tiers respectively, alongside burst limits and existing endpoint-specific restrictions. The change primarily affects heavily automated workloads, especially scripts and agents that do not send credentials, since paid subscriptions do not apply unless each request is authenticated. GitLab recommends using tokens, service accounts for distinct non-human workloads, request batching and caching, monitoring rate-limit headers, and honoring 429 retry instructions with backoff logic. Although GitLab says most ordinary browsing, Git activity, and CI usage should remain unaffected, critics argue that strict per-IP anonymous limits may disproportionately affect public open-source projects and organizations sharing network addresses while sophisticated scrapers can rotate IPs. The policy reflects a broader industry shift toward metering platform capacity based on authenticated identity, similar to approaches used by GitHub and Docker Hub.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.