
Reddit Is Killing RSS and Unauthenticated API Endpoints: What Breaks in Your Stack
Reddit is reportedly closing off the two access paths that quietly hold up a lot of developer tooling — RSS feeds and unauthenticated .json endpoints — with tighter gating on Old Reddit as a third front. This post is the audit I would run on my own stack today: how to find every Reddit dependency you own, which integrations break first when those endpoints go dark, and how to move reads behind an adapter or OAuth before it turns into an outage.
My source is a news write-up — Reddit Tightens Old Reddit Access and Is Killing RSS and Public API Over AI Scraping and Spam (Windows Report, dated 2026-10-01) — framed around AI scraping and spam pressure. I do not have a Reddit engineering post or an r/modnews announcement in front of me, so treat the scope and dates as unconfirmed. What is not uncertain is the engineering consequence: if you depend on these surfaces, you depend on something you do not control, with no contract and no deprecation guarantee.
Below is an honest split between what the reporting claims and what I could actually verify.
Which Reddit Access Surfaces Are Reportedly Shutting Down
The three access surfaces at risk: RSS, unauthenticated JSON, and Old Reddit HTML
Three different doors into the same building, and they break differently.
- RSS/Atom (
https://www.reddit.com/r/<sub>/.rss,/user/<name>/.rss, comment feeds). No auth, no OAuth app, no User-Agent ceremony — which is exactly why feed readers, Slack/Discord bridges, and newsletter jobs use it. - Unauthenticated JSON (
/r/<sub>/new.json,/comments/<id>.json,/search.json). Same shape as the official API, minus the token. It is what most weekend-script dashboards, moderation bots, and research scrapers call. - Old Reddit HTML (
old.reddit.com). The fallback scrape target. Once HTML is gated, HTML parsers are dead in a way that fixing a request header will not solve.
The detail that matters here: RSS and .json are keyless. That is their value and their vulnerability. Anything keyless is also unaccountable, which makes it cheap to remove.
What the reporting claims versus what I could verify
Per the report: Reddit is tightening Old Reddit access and removing RSS and public API access, with AI scraping and spam given as the motivation. That is the claim.
On the rollout itself, I verified nothing. I found no Reddit-side artifact — no changelog entry, no Data API terms revision, no r/modnews post — inside the material I was given. My own probes did not trigger a hard block either, though they were shallow and clearly not representative of every edge. So: the direction is plausible and consistent with the platform-tightening pattern of the last few years; the specifics — which endpoints, which dates, whether it is global or staged — are inference on my part, not confirmed fact.
Do not build a migration plan on my summary. Build it on the probes below, run from your own infrastructure.
Which Reddit Integrations Break First
Feed readers, RSS-to-Slack/Discord bridges, and newsletter pipelines
These break loudest and first, because there is no alternative path baked in. An RSS poller has no OAuth flow to fall back on. The failure mode is usually a silent empty feed rather than an error, which is worse — your digest job keeps running and posts nothing, and you find out from a reader.
Bots, dashboards, and moderation tooling that poll .json endpoints
Rate-limited .json polling has been the informal contract for years. When it closes, breakage is a mix of 403/401 responses and silent shape changes if the response becomes a login redirect that your HTTP client happily follows and then tries to parse as JSON. Watch for Content-Type flipping to text/html — that is the tell.
Research, archival, and dataset-building scripts
This group gets the worst deal. Archival work is long-running and often keyless by design, because you cannot OAuth on behalf of thousands of users. If the endpoints close, in-flight datasets get truncated mid-collection, and a truncated dataset is worse than none if nobody records where the gap is.
How to Audit Your Stack for Reddit Dependencies
Finding Reddit API calls in your codebase with ripgrep
Start by finding every call site. Most teams are surprised by how many sit in notebooks and cron files rather than the main repo.
rg -n --hidden -g '!node_modules' -g '!.git' \
-e 'reddit\.com' -e 'old\.reddit' -e '\.rss' -e 'redditusercontent' .
The output shape to expect (illustrative sample, not a real repo dump):
scripts/digest.js:14: const feed = "https://www.reddit.com/r/node/.rss";
jobs/karma-tracker.py:31: url = f"https://www.reddit.com/user/{u}/about.json"
infra/dashboards.tf:88: REDDIT_BASE = "https://old.reddit.com"
notebooks/labeling.ipynb: "https://www.reddit.com/r/MachineLearning/top.json?t=day"
Now classify each hit by whether it already carries a token. Anything with Authorization: Bearer is on OAuth; everything else is on the endangered list.
Probing Reddit endpoints with curl: status codes, redirects, and User-Agent gating
Probe with a unique, descriptive User-Agent — generic ones get gated first — and follow redirects explicitly so you can see them instead of having your client hide them.
#!/usr/bin/env bash
## Probe the three surfaces. Keep this low volume: a handful of requests,
## once. Do not loop this against production Reddit.
UA="hackyjs-audit/0.1 (+https://example.com/contact)"
probe() {
label="$1"; url="$2"
# -sS: quiet but show errors. -D -: dump headers to stdout.
# -o /dev/null: we only care about status + headers here.
# -w: print the final URL so redirect-to-login is visible.
printf '\n=== %s ===\n' "$label"
curl -sS -A "$UA" -D -o /dev/null \
-w 'final_url=%{url_effective} http=%{http_code} type=%{content_type}\n' \
"$url" | grep -Ei '^(HTTP/|location:|content-type:|final_url=|retry-after:|x-ratelimit)'
}
probe "rss" "https://www.reddit.com/r/node/.rss"
probe "json" "https://www.reddit.com/r/node/new.json?limit=5"
probe "old-html" "https://old.reddit.com/r/node/"Run it and read three things, in order:
- Final HTTP status. 200 means still open. 401/403 means auth is now mandatory. 429 means you are rate-limited, which is a different problem and usually fixable with a token.
location:andfinal_url=. A redirect tohttps://www.reddit.com/login/or an interstitial is the clearest sign of a soft gate — the endpoint still answers, just not to you.content_type:. If.jsonstarts returningtext/html, your parser will throw somewhere far from the real cause. Guard on content type before parsing.
I could not reproduce a hard block when I probed, so I am deliberately not pasting a transcript and calling it evidence — that would be inventing output. Capture your own from the network that actually runs your jobs; egress IP and UA both matter, and a datacenter IP will see a different answer than your laptop.
Mapping each surface to its typical caller and breakage mode
| Surface | Typical caller | Breakage mode when gated |
|---|---|---|
/r/<sub>/.rss | Feed readers, Slack/Discord bridges | Silent empty feed, no error |
/.json (unauthenticated) | Dashboards, moderation bots, scrapers | 401/403, or redirect parsed as JSON |
old.reddit.com HTML | Fallback scrapers, HTML parsers | Selector breakage, login interstitial |
| Official API (OAuth) | Registered apps | Rate limits, key revocation, terms changes |
Why "Just Use the Official API" Is Not a Drop-In Fix
I have seen this advice handed out as if it were a one-line fix. It is not, and saying so plainly matters more than sounding agreeable.
OAuth app registration, User-Agent rules, and rate-limit budgeting
Moving from .json to OAuth means a registered app, a client ID and secret, a token refresh loop, and a distinct, descriptive User-Agent — the API rules page is explicit that generic or shared User-Agents are not acceptable. The published free tier for the Data API has been documented at roughly 100 queries per minute per OAuth client ID; check the current terms, because that number has moved before and may move again.
Then there is the non-technical part: a registered app is an identity you are accountable for. A blocked key becomes a business outage rather than a broken script. For a hobby digest, that trade is bad.
Where the official API fits and where it clearly does not
The official API fits: posting, moderation actions, per-user authenticated features, and sustained polling with a real budget behind it.
It plainly does not fit:
- Bulk archival. One OAuth client at 100 QPM cannot crawl a decade of comments in any reasonable window, and the terms constrain bulk collection.
- Keyless one-off scripts. The entire point was that a five-line script worked. Adding OAuth makes it a project.
- Casual research and student work. OAuth registration, secret management, and terms review is a real barrier that changes who gets to study public discussion.
Reddit Migration Options Ranked by Effort and Risk
Move to OAuth where the use case genuinely fits
Best effort-to-risk ratio when you are doing authenticated actions or moderate-volume polling on your own behalf. Cost: registration, secret storage, refresh handling, rate budgeting. Do this first for anything that is genuinely an app.
Cut Reddit dependence with caching, an adapter layer, and vendor-neutral feeds
The highest-leverage engineering work, and the part that survives the next platform doing this. Put every platform read behind one interface:
// reddit-source.js — the only file that knows Reddit exists
export async function fetchSubredditPosts(sub, limit = 25) {
const url = `https://www.reddit.com/r/${sub}/new.json?limit=${limit}`;
const res = await fetch(url, { headers: { "User-Agent": process.env.REDDIT_UA } });
if (!res.ok) throw new Error(`reddit fetch failed: ${res.status}`);
const type = res.headers.get("content-type") || "";
if (!type.includes("application/json")) {
// Redirect-to-login or interstitial. Fail loudly instead of parsing HTML.
throw new Error(`reddit returned non-JSON content-type: ${type}`);
}
return (await res.json()).data.children.map((c) => c.data);
}
Swap the body once when the surface closes. Also add a per-URL cache with a TTL and a stale-while-error path so a gate degrades to old data instead of an empty digest.
Licensed data, archives, and self-hosted alternative feeds
For archival and research, the durable options are licensed datasets, institutional agreements, and self-hosted mirrors — including participation in community archives and Internet Archive snapshots where licensing allows. Heavier, but they are the only options that do not reset every time a platform changes its mind.
Designing So the Next Platform Shutdown Hurts Less
Three rules I now apply by default:
- Treat third-party endpoints as leased, not owned. Anything keyless and undocumented gets a deprecation date you cannot see. Assume it.
- Never let a platform's schema reach your domain model. Normalize at the boundary. The code above returns plain post objects; nothing downstream imports Reddit's shape.
- Make degradation observable. A feed that returns zero items should page someone, because silence is the failure mode here, not a stack trace.
What I Confirmed Versus What I Did Not Test
Confirmed from the source I was given: the report states Reddit is tightening Old Reddit access and removing RSS and unauthenticated public API access, citing AI scraping and spam. Attribution: Windows Report, dated 2026-10-01, surfaced via Google News.
Not confirmed: I found no Reddit-side announcement in my material, so the precise endpoint list, geographic staging, and effective dates are unknown to me. Likewise, my own network never produced a block (see the probe section above).
Tested by me: nothing in this post depends on my own probe results — I deliberately left the output blocks as commands for you to run, because pasting invented curl output would be worse than having none.
My position: if the reporting holds, this is a real breaking change for keyless integrations, and the "just use the official API" answer is wrong for archival, keyless scripting, and casual research. The correct response is not a Reddit-specific patch — it is moving platform reads behind an adapter, adding caching, and accepting that public platform data is a convenience you rent.
Further Reading
- Reddit Data API documentation — endpoint reference, including the
.jsonlistings you are probably calling. - Reddit API rules — User-Agent requirements and rate-limit behavior.
- Reddit OAuth2 documentation — the registration and token flow you would migrate to.
- Reddit API Terms of Use — the terms that govern bulk collection and commercial use.
- RSS 2.0 specification — useful if you are building a feed normalizer.
Closing Take: Rent Public Data, Own Your Adapter
The headline is about AI scraping and spam, but the engineering lesson is older than this story: any integration built on an unauthenticated, undocumented surface is a temporary integration. Run the ripgrep, run the probes from your production network, and write down what you find today — so that when the announcement is official, your migration is a diff in one adapter file instead of an archaeology project.


