The API is default rate-limited, so spamming page requests shouldn’t be possible; not behaving like a bot is the relatively easy part – doing so cost-effectively is harder and what I spend more time optimizing for.