Product2026-09-143 min read

No Sign-In Required: How Anonymous Rate Limiting Keeps a Free Tool Free

Catalog tools and anonymous /api/v1 calls need no account. Hosted responses carry X-RateLimit-Limit, Remaining, and Reset; HTTP 429 adds Retry-After too.

PDF123 · Updated 2026-09-17

PDF123 keeps an upload-and-download path with no account. The same operations also sit under /api/v1/ so a script can call them without a person clicking Process. Anonymous use needs no API key. Rate limits keep that surface from becoming an unbounded free host.

Anonymous is the default path

Drop a file on a tool page such as Compress or Merge and run it. Anonymous REST under /api/v1/ works the same way for catalog tools. Endpoints under /api/v1/general/, /api/v1/misc/, /api/v1/security/, /api/v1/convert/, and /api/v1/filter/ are the anonymous tool prefixes; every catalog tool in the portal maps into those paths.

Signing in exists so you can create a personal API key for automation, not so Process becomes a paywall. The browser form and the HTTP contract stay aligned: each tool page’s “Call this from code” block builds a curl from the same fields the form sends.

Admin, user-profile, and other non-tool routes are outside those prefixes. An anonymous caller that hits a gated path gets an auth failure, not a free ride through the whole API surface.

What the headers say

Every hosted API response advertises budget (implemented on pdfx-server):

  • X-RateLimit-Limit: period cap advertised for this response
  • X-RateLimit-Remaining: budget left in the current period
  • X-RateLimit-Reset: reset marker for the window (read the value; do not assume a calendar day)

On HTTP 429, Retry-After tells a polite client when to try again. Quota failures use the structured rate_limited problem code under Developers errors, with the same application/problem+json shape as other API failures. A script can branch on the code without scraping an HTML error page.

Numeric caps can change with deployment settings. The headers on a given response are the source of truth, not a blog snapshot. A client that hard-codes a daily number from this article will be wrong the next time an operator retunes the period. Prefer reading X-RateLimit-Remaining after each call and backing off when it approaches zero.

Why a free tool still caps callers

Without caps, anonymous endpoints become someone else’s batch farm. Limits keep one-off jobs usable while heavier or private workloads move to keys or self-host.

Caps also protect shared CPU for ops that are genuinely expensive: large merges, OCR that returns Markdown from scans (text/markdown, not a re-layered PDF), and multi-step POST /api/v1/pipeline runs. The product choice is “anonymous and finite,” not “anonymous and unlimited.”

Anonymous access is still temporary processing: uploads are handled for the job and cleaned up when the result is ready. Rate limiting is about fairness of capacity, not about inventing a long-term document store behind a free login wall.

Keys change identity, not the catalog

Create a key from Developers when you need a stable caller identity, Idempotency-Key retries that must not double-run work, or a self-hosted server with a fixed global key (SECURITY_CUSTOMGLOBALAPIKEY on your box). OpenAPI remains at /v1/openapi.json on whichever base URL you hit.

MCP at /mcp follows the same catalog and the same key story for automation clients. The operations stay the same whether the caller is anonymous or keyed. Auth and quota are what change.

For the four handles on one op (browser, curl, MCP, CLI), see Same operation, four clients. For moving the whole surface onto your network when caps or retention are not enough, see What self-hosting actually buys you.

Open tool
Process in the browser — no watermark, files removed after the job.
Open tool