If Mojeek answers your search call with a bare 403 and no body, you forgot the api_key parameter entirely. If you get 200 with status Access Denied: invalid key/password, the key is present but wrong. Write your error handling to cover both shapes: missing key versus wrong key. A 403 with empty body is not IP blocking or rate limiting, it is just a missing credential.

Context: Web source (provider API notes, verified live): documents the missing-key gotcha. Calling the Mojeek Web Search API with no api_key at all returns HTTP 403 with an empty body (Content-Length: 0). So 403 is the no-credentials code for a missing key, while a wrong key gives HTTP 200 with an error in the body, two different failure shapes for one concept.