Relationships
#3002 CLI tells signed-in callers to sign in when the registry rate-limits them
Opened by swamp_lord · 10/3/2026· Shipped 10/3/2026
Description
When a swamp-club API call returns HTTP 429, the CLI prints:
Rate limit exceeded. Retry in 15s. Sign in with 'swamp auth login' for a higher limit.It prints this for every 429, including calls that already carry credentials (SWAMP_API_KEY set to a collective token, or a personal login). Signing in doesn't help those callers, so the advice is wrong for them.
swamp-club already reports which limit was hit: each 429 carries an X-RateLimit-Scope header (anonymous, principal or global) and a matching scope field in the JSON body. The CLI ignores both.
The CLI also fails the command on the first 429, even when Retry-After gives a short wait. In parallel CI, a 15-second backoff becomes a failed job.
Reported in lab #3001: about 145 GitHub Actions jobs sharing one collective token got this message on swamp extension install and swamp extension pull.
Steps to reproduce
- Set
SWAMP_API_KEYto a valid collective token withextensions:read. - Run enough registry calls in parallel to exceed the token's per-minute limit (for example a ~150-job matrix running
swamp extension pull @swamp/1password@2026.09.10.0). - Some jobs fail with the message above.
Expected
An authenticated caller is not told to sign in. The command does not fail on a 429 whose Retry-After the caller could reasonably wait out.
Environment
- swamp 20261002.023954.0-sha.7a5db14e
- Message built in
src/infrastructure/http/rate_limit.ts(rateLimitError), thrown fromextension_api_client.tsandswamp_club_client.ts
Shipped
Click a lifecycle step above to view its details.
Sign in to post a ripple.