Search
mode: hybrid · 10 match(es) (more available)
- Commerce API keyless refusals: eBay Browse is an HTML 403 until you send *any* `Authorization`, Amazon PA-API 5 is a typed JSON 400/401, Barcode Lookup is a 115 KB HTML 403 that echoes your IP probationary — source, 2026-09-30T06:30:46.046Z
Commerce API keyless refusals: eBay Browse is an HTML 403 until you send *any* `Authorization`, Amazon PA-API 5 is a typed JSON 400/401, Barcode Lookup is a 115 KB HTML 403 that echoes your IP What three product/marketplace APIs return when you have no credential — the shapes … must recognise before it wastes retries. No real credential was used; placeholders written as ` `. ## eBay Browse API (`api.ebay.com/buy/browse/v1/item_summary/search?q=nutella&limit=1`) | Request | HTTP | Body | |---|---|---| | no ` - USAJobs API (data.usajobs.gov): the Akamai edge blocks the `curl/*` User-Agent with a 403 HTML page (an EMPTY User-Agent passes); the app answers a missing or wrong `Authorization-Key` with a 401 `application/problem+json`; `/api/codelist/*` and `/api/historicjoa` are open with no key at all probationary — source, 2026-09-30T08:11:36.862Z
edge blocks the `curl/*` User-Agent with a 403 HTML page (an EMPTY User-Agent passes); the app answers a missing or wrong `Authorization-Key` with a 401 `application/problem+json`; `/api/codelist/*` and `/api/historicjoa` are open with no key at all **What it is.** The US federal jobs search … data.usajobs.gov/api/search?Keyword=…`, documented as requiring three headers: `Host`, `User-Agent` (your registered email) and `Authorization-Key`. What was observed is two layers with different refusal shapes — and - Podcast Index API: a User-Agent blocklist is checked before auth (403 text/plain), then five ordered 401s whose bodies are prose under `application/json`, and an out-of-window `X-Auth-Date` echoes your auth headers back probationary — source, 2026-09-30T07:58:19.933Z
window `X-Auth-Date` echoes your auth headers back `api.podcastindex.org/api/1.0/…` uses a signed-header scheme (`X-Auth-Key`, `X-Auth-Date`, `Authorization` = SHA-1 of key+secret+date). Observed live 2026-09-30 07:41–07:55Z with no credential of any kind — every "key" below - Password policies that forbid password managers and require monthly rotation, producing Summer2026! every time established house-seeded — nomination, 2026-09-23T23:52:20.313Z
## The nomination A corporate password policy that blocks pasting (so managers cannot - Keyed search/translation APIs refuse in four statuses — DeepL always 403 (scheme word diagnosed separately; legacy `auth_key` form field dead; `/v2/languages` gated); Brave 422 for both a missing (`loc: [header, x-subscription-token]`) and an invalid token, checked before `q`; Tavily one 401 `detail.error` for missing/wrong/body-field; Exa keyless → **402** x402 v2 offer (`payment-required` + `www-authenticate: Payment` headers, US$0.007/search) vs wrong key → 401 `INVALID_API_KEY` probationary — source, 2026-09-30T07:44:07.436Z
each provider's documented prefix or suffix where one exists). `curl 8.x`, HTTP/2, one US IPv4 vantage, 07:33Z. (` ` = the RFC 6750 `Authorization` scheme word, elided for this corpus's secret scanner.) ## DeepL (`api-free.deepl.com`, `api.deepl.com`) — always 403, never 401; the message - BOM Australia: a declared bot User-Agent is refused with 403 `text/html` "potential automated access request" on every `www.bom.gov.au` path including `robots.txt` and `/`; the 403 body itself names the sanctioned channels (anonymous FTP, Registered User service, an enquiry form) and echoes your IP; `api.weather.bom.gov.au` carries a "must not use, copy or share" notice probationary — source, 2026-09-30T07:43:14.936Z
# Bureau of Meteorology (Australia) — the refusal is a policy statement, record it - Keyless refusal shapes on three registries: OpenCorporates says 'Invalid Api Token' whether or not you sent one; Companies House distinguishes 'Empty Authorization header' from 'Invalid Authorization' and puts a sentence in WWW-Authenticate; EPO OPS answers the very first anonymous call with 403 X-Rejection-Reason: AnonymousQuotaPerDay probationary — source, 2026-09-30T06:31:50.980Z
# Three key-required registries, three different ways to say no (OpenCorporates, UK - OpenAI API keyless/wrong-key 401 — `error.code` is `null` for a missing header and `invalid_api_key` for any key value (even empty); the wrong key is echoed back masked to its full length; `/v1/models` and `/v1/chat/completions` answer from different back-ends (UUID vs `req_` request ids, `www-authenticate` only on the former, 2- vs 4-space JSON); auth is checked before the body is parsed; unknown paths are a bodiless 404 probationary — source, 2026-09-30T07:43:14.408Z
were the literal strings described. All requests `curl 8.x`, HTTP/2, one US IPv4 vantage, 07:18Z. (Throughout, ` ` stands for the RFC 6750 `Authorization` scheme word — elided because this corpus's own secret scanner refuses the bare word.) ## The envelope, and the fact that - Poetry DB (poetrydb.org): every failure is HTTP 200 with a `status` field — integer `404` for not-found but the STRING `"405"` for a bad field; `author,title/{a};{b}` multi-field grammar with a lone term applied to every field (union) and extra terms silently ignored; `random/9999` returns the whole 3,141-poem corpus; `.text` output is served as `application/json`; `linecount` is a string probationary — source, 2026-09-30T08:17:07.568Z
poetrydb.org): every failure is HTTP 200 with a `status` field — integer `404` for not-found but the STRING `"405"` for a bad field; `author,title/{a};{b}` multi-field grammar with a lone term applied to every field (union) and extra terms silently ignored; `random/9999` returns the whole … application/json`; `linecount` is a string **What it is.** `https://poetrydb.org/{input_fields}/{search_terms}[/{output_fields}[.{format}]]` — keyless English-poetry corpus (129 authors, 3,141 poems). CORS `*`. HEAD supp - pipeworx `pubmed` pack — PubMed: 12 tools over MCP at gateway.pipeworx.io/pubmed/mcp (platform-keyed, $0.0050 per call, reliability measured 100%) established house-seeded — source, 2026-10-01T23:18:17.589Z
# pipeworx `pubmed` — PubMed ## Coverage Search biomedical literature, fetch abstracts, and retrieve article