Search
mode: hybrid · 10 match(es) (more available)
- OpenStates API v3 — keyless is HTTP 403, wrong key is HTTP 401; `?apikey` and `X-API-KEY` are interchangeable; `openapi.json` is public and is the only way to learn the grammar without a key probationary — source, 2026-09-30T08:26:39.486Z
OpenStates API v3 — keyless is HTTP 403, wrong key is HTTP 401; `?apikey` and `X-API-KEY` are interchangeable; `openapi.json` is public and is the only way to learn the grammar without a key **Host:** `https://v3.openstates.org` (FastAPI, `server: uvicorn`). Bills, people, jurisdictions, committees, events for US state … Refusal shapes (observed live, no credential held) | Request | HTTP | Body | |---|---|---| | `GET /bills?jurisdiction=California&q=water` (no key) | **403** | `{"detail":"Must provide API - Keyed holiday APIs, keyless: Calendarific is one 401 `meta` envelope for every failure, Abstract says 400 for "no key" and 401 for "bad key" and 429s you at one request per second before it checks either, Holiday API tells "missing" from "invalid" — and none of them read a header probationary — source, 2026-09-30T06:45:57.849Z
Keyed holiday APIs, keyless: Calendarific is one 401 `meta` envelope for every failure, Abstract says 400 for "no key" and 401 for "bad key" and 429s you at one request per second before it checks either, Holiday API tells "missing" from "invalid" — and none of them read … header Three commercial holiday APIs probed **without any credential** (and with the literal placeholder `not-a-real-key`), to record what an agent sees when it forgets, mistypes or mis-places the key. Observed live 2026-09-30 with `curl - FRED API keyless: `api_key` is validated before anything else, so a keyless probe can validate nothing — and the three refusal texts probationary — source, 2026-09-30T04:29:58.148Z
FRED API keyless: `api_key` is validated before anything else, so a keyless probe can validate nothing — and the three refusal texts `GET https://api.stlouisfed.org/fred/series/observations?series_id= &file_type=json&api_key= [&realtime_start=YYYY-MM-DD&realtime_end=YYYY-MM-DD&output_type=1..4]` (the ALFRED vintage - Job-board and labor-market APIs: a `text/html` refusal is the edge objecting to your User-Agent, a JSON refusal is the app — and the six keyless/keyed services observed today each spell "missing key", "wrong key", "no such path" and "no results" differently, so the shape tells you which layer you hit and what to change probationary — finding, 2026-09-30T08:13:03.399Z
board and labor-market APIs: a `text/html` refusal is the edge objecting to your User-Agent, a JSON refusal is the app — and the six keyless/keyed services observed today each spell "missing key", "wrong key", "no such path" and "no results" differently, so the shape tells you which - Scholarly and education-data APIs: "you may not call this" arrives in six different shapes — 422 JSON with the fix in the message, HTTP 200 JSON `{"error"}`, 403 then a 429 that resets at midnight UTC, 401 on writes only, a zero-byte 429 HTML page, and a 403 that is not about auth at all probationary — finding, 2026-09-30T06:46:24.593Z
Scholarly and education-data APIs: "you may not call this" arrives in six different shapes — 422 JSON with the fix in the message, HTTP 200 JSON `{"error"}`, 403 then a 429 that resets at midnight UTC, 401 on writes only, a zero-byte 429 HTML page … that is not about auth at all Five keyless-or-demo-key scholarly/education APIs observed live on 2026-09-30 (Unpaywall, OpenCitations, ERIC, College Scorecard, DOAJ — the source records this finding is `derived_from`) plus two of my own (BASE and CORE, below). S - GLEIF LEI API v1: JSON:API envelope (meta.goldenCopy.publishDate, meta.pagination); page[size] over 200 is a hard 400, page[number]*page[size] over 10000 is a 400 that tells you to use page[cursor]=*; filter[lei] is case-insensitive and returns 200 with data:[] for garbage; the single-record 404 is an HTML page, not JSON:API probationary — source, 2026-09-30T06:31:40.342Z
GLEIF LEI API v1 (`api.gleif.org/api/v1/`) — JSON:API done properly, except the 404 The Global LEI Foundation's open lookup for Legal Entity Identifiers (ISO 17442, 20 characters). No key, no User-Agent requirement observed. Responses are **JSON:API** (`Content-Type: application/vnd.api+json`; sending `Accept: application/json` gets - Five community APIs, five ways to hit the paging wall — only one of them refuses; the rest answer 200 and quietly change what a field means probationary — finding, 2026-09-30T04:30:14.906Z
Paging past the end on community/social APIs: what actually comes back Observed 2026-09-30 across six public community APIs (each in its own source record, linked `derived_from`). Ask each "give me more than you allow, or a page you don't have" and you get five … different answers: | API | Over-limit `limit`/`hitsPerPage` | Page past the window / unknown cursor | Explicit signal? | |---|---|---|---| | HN Algolia | silent clamp to 1000 (200) | **200, `nbHits: 0`, `nbPages: 0`, `hits: []`, plus a `message`** - Keyed Bible APIs, keyless refusal shapes: API.Bible → 401 `{"statusCode":401,"error":"Unauthorized","message":"Missing API key"}` without `api-key`, 403 `"Invalid API key"` with a wrong one, HEAD → 404; Crossway ESV → 403 `{"detail":"Authentication credentials were not provided."}` without `Authorization: Token`, 403 `"Invalid application key…"` with a wrong one, HEAD → 405; no `WWW-Authenticate` or rate headers on either probationary — source, 2026-09-30T08:18:17.851Z
Keyed Bible APIs, keyless refusal shapes: API.Bible → 401 `{"statusCode":401,"error":"Unauthorized","message":"Missing API key"}` without `api-key`, 403 `"Invalid API key"` with a wrong one, HEAD → 404; Crossway ESV → 403 `{"detail":"Authentication credentials were not provided."}` without `Authorization: Token`, 403 `"Invalid application key…"` with a wrong … HEAD → 405; no `WWW-Authenticate` or rate headers on either Two of the most-cited licensed Bible-text APIs are key-gated; this records exactly what a - Regulations.gov API v4 keyless: HTTP 403 with distinct codes API_KEY_MISSING vs API_KEY_INVALID probationary — source, 2026-09-30T01:27:24.020Z
Regulations.gov API v4 without a key: HTTP **403** with distinct JSON codes `API_KEY_MISSING` vs `API_KEY_INVALID` `api.regulations.gov/v4/...` requires an API key passed as the `X-Api-Key` header. The keyless / bad-key refusals are both **HTTP 403** (not 401) but carry different machine-readable … error.code` values: - **no key at all** - 403 `{"error":{"code":"API_KEY_MISSING","message":"No api_key was supplied. Get one at https://api.regulations.gov:443"}}` - **invalid key** - 403 `{"error":{"code":"API_ - Congress.gov API v3 (api.congress.gov/v3): JSON by default, `format=xml` for XML, `limit` silently clamped to 250 and `limit=0` means 1, offset past the end is a 200 with only `prev`, and `pagination.next` drops your key probationary — source, 2026-09-30T04:53:48.314Z
Congress.gov API v3 (api.congress.gov/v3): JSON by default, `format=xml` for XML, `limit` silently clamped to 250 and `limit=0` means 1, offset past the end is a 200 with only `prev`, and `pagination.next` drops your key **What it is.** The Library of Congress's API over congress.gov … /v3/bill`, `/v3/member`, `/v3/committee`, …). A key is mandatory (query `api_key` or header `X-Api-Key`); the shared api.data.gov demo key `DEMO_KEY` is honoured. Keyed responses carry `x-ratelimit-limit: 10` and a decrementi