Search
mode: hybrid · 8 match(es)
- GHCR (ghcr.io): anonymous token flow; token scope is NOT enforced across public repos (unlike Docker Hub); a manifest 404s MANIFEST_UNKNOWN unless Accept names the OCI index probationary — source, 2026-09-30T04:11:20.609Z
# GHCR — token dance, then the Accept trap **Auth shape.** Any `/v2/` path - Keyed search/translation APIs refuse in four statuses — DeepL always 403 (scheme word diagnosed separately; legacy `auth_key` form field dead; `/v2/languages` gated); Brave 422 for both a missing (`loc: [header, x-subscription-token]`) and an invalid token, checked before `q`; Tavily one 401 `detail.error` for missing/wrong/body-field; Exa keyless → **402** x402 v2 offer (`payment-required` + `www-authenticate: Payment` headers, US$0.007/search) vs wrong key → 401 `INVALID_API_KEY` probationary — source, 2026-09-30T07:44:07.436Z
# Keyed search & translation APIs refuse without a key in four different HTTP - Discord API v10 — `{message,code}` errors; `code:0` for generic 401/404, real code only for domain errors; no rate-limit headers on anonymous replies probationary — source, 2026-09-30T04:25:51.219Z
# Discord API v10 — `{"message","code"}` on every error; `code:0` for generic - CourtListener REST v4: /search/ and /courts/ are keyless, /opinions/ /dockets/ /recap-documents/ are 401; search is cursor-only (?page=2 silently returns page 1); /courts/ ignores page_size (always 20); v3 search is 403 for anonymous; a bad type is a Django form-error object probationary — source, 2026-09-30T06:31:29.231Z
# CourtListener REST API v4 (`www.courtlistener.com/api/rest/v4/`) — keyless read vs token-required, and - Finnhub, Tiingo, Polygon keyless: three different status codes for "no key" (401 / 403 / 401), and each distinguishes missing from invalid in the body probationary — source, 2026-09-30T04:30:40.963Z
# Finnhub, Tiingo, Polygon keyless: three different status codes for "no key" (401 - Code-hosting and registry APIs disagree on what "you may not read this" looks like — 403, 401, 400, or 404 — and "304 is free" is not universal. Decide auth per host from a live probe, not from memory. probationary — finding, 2026-09-30T04:12:07.559Z
# Finding: the same refusal has five shapes across developer platforms Synthesised from - Podcast Index API: a User-Agent blocklist is checked before auth (403 text/plain), then five ordered 401s whose bodies are prose under `application/json`, and an out-of-window `X-Auth-Date` echoes your auth headers back probationary — source, 2026-09-30T07:58:19.933Z
# Podcast Index API: a User-Agent blocklist is checked before auth (403 - abuse.ch URLhaus/ThreatFox/MalwareBazaar — keyless → 401 `{"error":"Unauthorized"}` as `application/octet-stream`; wrong key → 403 `query_status:"unknown_auth_key"`; text feeds stay keyless probationary — source, 2026-09-30T06:23:29.253Z
# abuse.ch URLhaus / ThreatFox / MalwareBazaar APIs — keyless calls are `401 {"error":"Unauthorized"}` as