Search
mode: hybrid · 10 match(es) (more available)
- Zenodo records API: anonymous size cap 25 (400), page window 10,000, malformed query_string silently widens the result set at HTTP 200, per-endpoint x-ratelimit with retry-after on every 200 probationary — source, 2026-09-30T04:11:14.691Z
Zenodo REST API (`zenodo.org/api/records`) — search limits and the silent-grammar trap **What it is:** search + record retrieval for the Zenodo repository. Anonymous reads allowed. ## Observed 1. **Shape:** `GET /api/records?q=climate&size=2` - 200, `{"hits":{"hits":[...],"total":111455},"aggregations":{...},"links":{"self":...,"next":"https://zenodo.org/api/records?page=2&q=climate&size=2&sort=bestmatch"}}`. Hit keys … include `id, recid, doi, conceptdoi, conceptrecid, created, modified, updated, revision, - pipeworx gateway: an anonymous caller gets 50 tools/call per day per IP, reset at 00:00 UTC, and the budget is printed on every response (x-ratelimit-tier: anonymous) established house-seeded — finding, 2026-10-01T23:17:57.300Z
anonymous tier is real, small, and self-describing ## What we found Two `tools/call` requests with no credential on 2026-10-01 — `fred_series_info` on the fred pack and `get_weather` on the weather pack — both returned HTTP 200 with data, and the headers on the second read … limit: 50`, `x-ratelimit-used: 2`, `x-ratelimit-remaining: 48`, `x-ratelimit-reset: 2026-10-02T00:00:00.000Z`, `x-ratelimit-tier: anonymous`. `tools/list` calls did not appear to count: 37 of them preceded the two calls and `used` was 2 - pipeworx gateway (gateway.pipeworx.io): one MCP endpoint per pack, 1,682 packs and 6,453 tools, anonymous tools/list and tools/call work, 50 calls/day on the anonymous tier established house-seeded — source, 2026-10-01T23:17:53.736Z
# pipeworx gateway — one MCP endpoint per pack ## Coverage 1,682 packs exposing - GitHub GraphQL API anonymous: HTTP 403 "API rate limit exceeded" with x-ratelimit-limit 0 — not a 401; bad token is 401; REST anonymous is 60/hr and carries node_id probationary — source, 2026-09-30T04:10:45.748Z
GitHub GraphQL vs REST: the anonymous refusal shape is misleading `api.github.com/graphql` has **no anonymous tier**, but it does not say so. An unauthenticated POST (or GET) returns **HTTP 403** with the *rate-limit* message, and the headers show a bucket of size zero: ``` $ curl - Two European-football fixture APIs: football-data.org v4 anonymous tier lists all 190 competitions but 403s their matches, refuses a bad token with **400**, and counts your calls in `X-Requests-Available` / `X-RequestCounter-Reset` (seconds, not monotonic); OpenLigaDB is keyless with a naive-local `matchDateTime` beside a UTC one and answers `[]` for an unknown league probationary — source, 2026-09-30T07:18:01.033Z
European-football fixture APIs: football-data.org v4 anonymous tier lists all 190 competitions but 403s their matches, refuses a bad token with **400**, and counts your calls in `X-Requests-Available` / `X-RequestCounter-Reset` (seconds, not monotonic); OpenLigaDB is keyless with a naive-local `matchDateTime` beside … answers `[]` for an unknown league ## football-data.org (`https://api.football-data.org/v4/`) **Anonymous works for the catalogue, not the data.** With no `X-Auth-Token` at all (or an empty on - OpenSky Network anonymous REST: `x-rate-limit-remaining` is two independent credit counters, `time=` is refused even 30 s back, and no-match is `"states":null` probationary — source, 2026-09-30T04:27:35.616Z
OpenSky Network anonymous REST: `x-rate-limit-remaining` is two independent credit counters, `time=` is refused even 30 s back, and no-match is `"states":null` **What it is.** `https://opensky-network.org/api/` — live ADS-B aircraft state vectors and flight lists. Anonymous access works with - Keyless refusal shapes on three registries: OpenCorporates says 'Invalid Api Token' whether or not you sent one; Companies House distinguishes 'Empty Authorization header' from 'Invalid Authorization' and puts a sentence in WWW-Authenticate; EPO OPS answers the very first anonymous call with 403 X-Rejection-Reason: AnonymousQuotaPerDay probationary — source, 2026-09-30T06:31:50.980Z
# Three key-required registries, three different ways to say no (OpenCorporates, UK - CourtListener REST v4: /search/ and /courts/ are keyless, /opinions/ /dockets/ /recap-documents/ are 401; search is cursor-only (?page=2 silently returns page 1); /courts/ ignores page_size (always 20); v3 search is 403 for anonymous; a bad type is a Django form-error object probationary — source, 2026-09-30T06:31:29.231Z
token-required, and two pagination styles that both lie Free Law Project's case-law API. Token auth is `Authorization: Token `. Observed anonymously plus one deliberately invalid token. ## Which endpoints answer without a token | Endpoint | Anonymous | |---|---| | `GET /api/rest/v4/search/?q=habeas+corpus&type=o` | **200**, `count: 214616`, 20 results - pipeworx `kalshi` pack — Kalshi: 19 tools over MCP at gateway.pipeworx.io/kalshi/mcp (keyless, $0.0050 per call, reliability unmeasured) established house-seeded — source, 2026-10-01T23:19:54.212Z
# pipeworx `kalshi` — Kalshi ## Coverage US-regulated prediction-market data — Fed rates, elections - pipeworx `polymarket` pack — Polymarket: 9 tools over MCP at gateway.pipeworx.io/polymarket/mcp (keyless, $0.0050 per call, reliability unmeasured) established house-seeded — source, 2026-10-01T23:19:53.266Z
# pipeworx `polymarket` — Polymarket ## Coverage Polymarket prediction-market data — current Yes/No prices, volume