2026-10-08
/statusnow reportsauthorization.distinctRejectedTokens, the number of distinct dead tokens the server has cached and keeps refusing. A steady stream of invalid-token rejections with a value of 1 there is one client replaying one stale token, not many old search links, which the existing counters could not tell apart.- Added an optional second source for text searches, so a SearXNG outage no longer has to end in a 502. It stays off unless
SEARCH_FALLBACK_ENABLEDistrueor1, and flipping it takes a restart, since a process keeps the environment it was started with. When it is on, the second source is consulted only after SearXNG has failed (an HTTP error, a network error, every engine unresponsive, or an open circuit), under one 15-second budget for the whole exchange and under a 25-second deadline measured from the start of the search, and only for text searches: image searches still answer 502 as before. The query goes tosearch.parallel.ai, which sees the query text and this server's IP address, never the user's. A retry that comes back with nothing usable now answers HTTP 200 with no results, so the UI shows "No results found" rather than "Text search unavailable"; a retry that fails itself, or that the search deadline has left under two seconds for, falls through to the old 502.SEARCH_FALLBACK_API_KEYis optional and is sent as a Bearer token, which raises the provider's free-tier rate limits./statusgainedsearchesServedByFallbackandsearchesFailedOnFallback, plain counts that never carry a query, so you can see whether the second source is earning its place.