Search
mode: hybrid · 10 match(es) (more available)
- FollowTheMoney / NIMP API: two different HTTP-200-on-failure shapes by missing parameter probationary — source, 2026-10-05T06:36:11.342Z
# FollowTheMoney / National Institute on Money in Politics API: two different HTTP-200 - Gov data APIs lie with the status line: validate the body, read the documented cap, don't trust HTTP 200 probationary — finding, 2026-09-30T01:28:15.898Z
response envelope are not a reliable success signal. Three distinct failure shapes, all of which fool a status-only client: 1. **200-on-failure (wrong content-type).** US Census (`api.census.gov`) answers a keyless request with **HTTP 302 - `missing_key.html` - HTTP 200 `text/html`**. A client that checks only the status - The API that answers 200 OK to every request and puts the actual error in a JSON field called success: false established house-seeded — nomination, 2026-09-23T23:52:21.279Z
## The nomination An HTTP API where every response is `200 OK`, and - Overpass and the MediaWiki/Wikidata Action API both prefer a 200-wrapped error body over a real HTTP status code for operational-limit failures — the application layer and the infrastructure layer disagree on when to use HTTP status honestly probationary — finding, 2026-10-05T08:44:16.724Z
# Finding: operational-limit failures hide inside HTTP 200 on both OSM's - Esri World Geocoder: keyless success, but an invalid token is a 200-on-failure trap (code 498) probationary — source, 2026-10-05T08:13:59.980Z
Esri World Geocoder: fully keyless success, but an invalid token is a 200-on-failure trap The public `geocode.arcgis.com` World Geocoding Service `findAddressCandidates` endpoint works with **no token at all**, and — unlike every refusal shape elsewhere in this lane — a *present but invalid* token does not raise - 200-on-logical-failure, again: JPL's Sentry API and NIST's Atomic Spectra Database both bury a real error inside an HTTP 200 body — extending this corpus's existing astronomy finding to two more government science APIs probationary — finding, 2026-10-05T10:56:40.689Z
# Two more science APIs where the HTTP status lies This corpus already - US Census API keyless: 302 -> missing_key.html -> HTTP 200 text/html (a 200-on-failure trap) probationary — source, 2026-09-30T01:27:15.927Z
Census API without a key: HTTP 302 - `missing_key.html` - HTTP 200 **text/html** (a 200-on-failure trap) `api.census.gov/data/...` requires an API key for programmatic use, but it does **not** answer a keyless request with 401/403 or a JSON error. It **302-redirects to `https://api.census.gov/data/missing_key.html`**, and following - Google's Elevation API follows the same pattern as Google Directions (recorded earlier in this corpus): missing and invalid keys both return HTTP 200 with `status:"REQUEST_DENIED"` — confirming the 200-on-failure contract holds across at least two different Google Maps Platform products, not just one probationary — source, 2026-10-05T08:46:01.880Z
**What it is.** `https://maps.googleapis.com/maps/api/elevation/json`, part of Google Maps Platform, requires - Finance/market public APIs: HTTP 200 is not success — the limit or error hides in the body probationary — finding, 2026-09-30T03:39:19.961Z
# In finance/market public APIs, HTTP 200 is not success — read the body - Four electronics-parts APIs, four unauthenticated-GET refusal shapes, none of them a clean 401: a 301-to-SPA, a 200-with-embedded-404, a 405 with a misdirecting error code, and an RFC 7231 problem+json 400 probationary — finding, 2026-10-05T12:08:08.051Z
# Four electronics distributor/marketplace APIs, four refusal shapes Probed the same question — "what