6 ms·
>Twitter’s statuses lookup API endpoint allows for a total of 1,200 API calls every 15 minutes. Each call allows the user to pass 100 ids for a total of 120,000
by nspkr 8y ago
>Twitter’s statuses lookup API endpoint allows for a total of 1,200 API calls every 15 minutes. Each call allows the user to pass 100 ids for a total of 120,000 id requests every 15 minutes using both APP auth [...]
Use the secret consumer keys from Twitter to bypass these limits: https://gist.github.com/shobotch/5160017 https://gist.github.com/shobotch/5160017
- throwawaymath 8y agoI can't imagine these will last long now that they've been posted in a comment on a front page HN story.
- gberger 8y agoThese are hardcoded in the apps. If they disable a key, they would need to release a new version of the app (ok), and all users would need to update (infeasible).
- deleted 8y ago[deleted]
- mrits 8y agoWouldn't they just enforce the limit with those keys as well?
- metildaa 8y agoSounds like a solid reason to not build around a platform that can arbitrarily kill your project or business. ActivityPub seems to be gaining traction, w/o the beholden to a single entity issue.
- jjeaff 8y agoA platform that can arbitrarily take down your business like a mobile app on iPhone or Android?
- Nextgrid 8y agoThey explicitly want to cripple third-party apps to push users to use their (awful) official clients, and their way of doing so is to enforce unreasonably low limits. If they were to do the same with their official clients they'd become unusable.
- ihuman 8y agoThe Twitter for Android key and secret is at least 8 years old https://twitter.com/kevinriggle/status/23932444186 https://twitter.com/kevinriggle/status/23932444186
- nspkr 8y agoI've been using them for years now.
- thsowers 8y agoSeems like a good way to get your IP blacklisted
- nspkr 8y agoIf you can't bypass an IP block then you need to git gud
- unityByFreedom 8y agoHackernews..
- mhfs 8y agoI worked with a company in the past that abused the twitter api to an unimaginable level from a single IP address. That was a few years ago but at the time I’m pretty sure their blacklisting was between inexistent and pathetic.
- tomglynch 8y agoUsing these keys?
- mhfs 8y agoNo. Different strategy.
- dev_dull 8y agoIt’s sad that you think this somehow reflects badly on Twitter. I appreciate a company that will opt to be conservative rather than ban-hammer innocent people on accident just to stop a single idiot.
- mhfs 8y agoI don’t think it reflects badly on Twitter, it was simply a remark on the state of their blacklisting at the time. I’m sure they could’ve done a lot better if they chose to. Sorry I didn’t expressed myself better.
- Thaxll 8y agoYou can do the same for the Reddit API, change the agent header and then you have unlimited API calls.
- thinkloop 8y agoHow would that work, I couldn't find much on the web?
- dewey 8y agoProbably by doing a mitm attack on the mobile app and using the headers used there.
- Thaxll 8y agoSame problem as the mobile app for Twitter, they can't block people that are not logged in the mobile app so they don't rate limit them.
- thinkloop 8y agoHow come they can block people on the web again?
- ihuman 8y agoJust be careful about how much you change it, since you could get banned. You might be able to get away with changing the app ID or version, but even that's risky. > NEVER lie about your user-agent. This includes spoofing popular browsers and spoofing other bots. We will ban liars with extreme prejudice. https://github.com/reddit-archive/reddit/wiki/API https://github.com/reddit-archive/reddit/wiki/API
- miki123211 8y agoCan we use them to get the streaming API back? I think the apps still use something like that.