Skip to content

SSE endpoint /a2a/events/stream rate-limited at 1 req/60s with IP-fallback bucket, preventing stable Evolver connection #610

Description

@ch3ch2cho2021

Summary

SSE endpoint /a2a/events/stream is rate-limited at 1 req/60s with an IP-fallback bucket, preventing Evolver from maintaining a stable long-lived SSE connection.

Problem

When connecting to the SSE event stream:

GET /a2a/events/stream?node_id=node_xxx

The server responds with 429 Too Many Requests even when node_id is provided as a query parameter:

{
  "error": "rate_limited",
  "retry_after_ms": 37446,
  "bucket": "sender_ip_fallback",
  "policy": {
    "key_prefix": "a2a_event_stream",
    "limit": 1,
    "window_ms": 60000
  }
}

Key observations

  1. Bucket is sender_ip_fallback — the SSE endpoint does not appear to recognize node identity from the node_id query param, so it falls back to IP-based rate limiting.
  2. Limit is 1 request per 60 seconds — far too restrictive for a long-lived SSE connection. Any reconnect attempt within the 60s window gets 429'd.
  3. Effect on Evolver: Evolver retries the SSE connection on disconnect, but because the rate limit window is only 1 req/min, the first request after window reset succeeds (connects), and all subsequent reconnect attempts within that minute are rejected. The result is intermittent SSE connectivity — connect, disconnect, 429 for 60s, connect again, repeat.

Expected behavior

  • SSE endpoint should recognize node_id (or Authorization: Bearer <node_secret>) and apply node-level rate limiting instead of falling back to IP.
  • Alternatively, the rate limit window for SSE connections should be widened significantly (SSE is a long-lived connection; rate-limiting connection establishment at 1/min makes stable streaming impossible).
  • A long-lived SSE stream should not consume short-request rate limit tokens at all.

Environment

  • Evolver version: latest (running on self-hosted server)
  • Hub URL: https://evomap.ai
  • Endpoint: GET /a2a/events/stream?node_id=...
  • Response headers show x-ratelimit-bucket: sender_ip_fallback, x-ratelimit-limit: 1

Request

Either:

  1. Make the SSE endpoint accept node identity (via node_id param or Authorization header) so it doesn't fall back to IP-based limiting, or
  2. Increase the SSE rate limit window substantially (e.g., 10 req/min minimum), or
  3. Exclude long-lived SSE connections from the general rate limiter entirely.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions