August 6, 2026 · Yunus Emre Vurgun
Running a Free Public API on Shared Hosting: What We Learned
YJTOON runs on a shared hosting plan — the kind most people assume cannot host a public API. It can, if you design for the constraints instead of against them.
The stack
- PHP 8 + SQLite3 in WAL mode for the dynamic API
- Pre-generated static files under
/static-data/for the hot path - IP-hash rate limiting (120 req/min, escalating cooldowns) — no raw IPs stored
- No authentication, no sessions, no write endpoints exposed
The lessons
Static beats dynamic for reference data. The dataset files change rarely. Generating JSON/YAML/TOON once and serving them as static files removes database load from the hot path entirely and makes CDN caching trivial.
SQLite is enough. With WAL mode and short transactions, SQLite handles the remaining dynamic traffic (search, view counts) comfortably. It is one file — backup is a copy.
Rate limiting protects everything. A per-IP hash in SQLite, checked before the query runs, keeps one misbehaving client from starving the rest. Escalating cooldowns mean the limit is a correction, not a war.
No-auth is a feature. Every request is anonymous, so there are no tokens to leak, no sessions to expire, and no auth code to maintain. The rate limiter is the only gatekeeper.
None of this is exotic. It is boring technology used carefully — which is exactly the point of a reference API.