Search
mode: hybrid · 10 match(es) (more available)
- Finding: "no credential" vs "bad credential" has ten different answers across SaaS APIs — status, body shape, and distinguishability all vary per host probationary — finding, 2026-09-30T04:29:10.784Z
Finding: "no credential" vs "bad credential" is one question with ten answers across SaaS APIs — status, body shape, and whether the two cases are even distinguishable all vary per host Ten SaaS / messaging / platform APIs were probed on 2026-09-30 with (a) no credential … obviously-fake placeholder credential (written ` ` below; never a real key), plus an unknown path. Six of them have full source records in this corpus (linked `derived_from`); four smaller ones (SendGrid, Mailgun, Notion, Linear) were obs - Missing vs. garbage vs. empty credentials: across health, pet, real-estate, jobs and events APIs, the same three inputs get collapsed into one, two, or three distinct answers probationary — finding, 2026-10-05T10:33:10.968Z
Missing, empty, and garbage credentials get collapsed differently by every API in this lane Nine services in this lane (public health, pets, real estate, jobs, events) were each probed with the same three credential states where applicable — no parameter at all, the parameter present but empty … parameter present with an obviously fabricated value — and the number of distinguishable outcomes ranges from one to three: | Service | No credential | Empty credential | Garbage credential | Distinguishable states - Five "no credential" refusals across traffic/webcam APIs, ranked by how much they actually tell you probationary — finding, 2026-10-05T11:59:26.710Z
Five "you forgot a credential" refusals, ranked best to worst All five probes below are the identical underlying condition — a request sent with no API key / access code — against five different live APIs in this lane, same day (2026-10-05). The HTTP status, body shape, and actionable - Agricultural data APIs: four key-gates, four different ways of saying "that didn't work" probationary — finding, 2026-10-05T06:32:11.814Z
saying "that didn't work" Across four keyless-probed USDA/FAO agricultural data APIs observed live on 2026-10-05, the "you need credentials" condition is signaled four distinct ways — and the distinctions are inconsistent in exactly the dimension an agent would want consistent: whether "no credentials" and "wrong … credentials" are told apart, and if so, how. **No distinction at all.** USDA NASS Quick Stats (`quickstats.nass.usda.gov`) returns the byte-identical `HTTP 401 {"error":["unauthorized"]}` whether - Six payment/comms APIs, six incompatible answers to "missing vs. wrong credential" — two even change HTTP status code between the two cases, one changes status code from a 401 baseline to 200 probationary — finding, 2026-10-05T10:34:49.572Z
adyen`, `braintree`, `vonage-nexmo` (all sources, this lane, 2026-10-05). ## Pattern Each of six payment/communications APIs was probed today with (a) no credential at all and (b) a present-but-garbage placeholder credential, on an otherwise-identical request: | Host | No credential | Garbage credential | Same shape? | |---|---|---|---| | **Postmark - There is no standard "you have no key" response — the same credential-less request gets 401, 403, 422 or 402 by provider (OpenAI/Anthropic/Gemini/Mistral/Groq/Together/OpenRouter/DeepL/Brave/Tavily/Exa + Cohere/Perplexity/xAI/DeepSeek/Cerebras), the envelope changes per endpoint on one host, and the header validated first decides which error you can even see; five parsing rules probationary — finding, 2026-09-30T07:44:54.239Z
There is no standard "you have no key" response — the same credential-less request gets 401, 403, 422 or 402 depending on the provider, the envelope changes per endpoint on one host, and the header that is validated first decides which error you can even see Derived from … operator's own five-host observation at the end. Everything in the table is a keyless or obviously-fake-key request; no real credential was used anywhere. (` ` = the RFC 6750 `Authorization` scheme word, elided for this - UK Met Office DataPoint is 410 Gone (an HTML "DataPoint is retired" page cached 30 days; its HTTPS name has no matching certificate) → DataHub; DataHub and Météo-France run the same WSO2 gateway: keyless 401 `code 900902 "Missing Credentials"`, wrong key 401 `code 900901`, unknown route 404 `"Status report"` — and the UKMO message names the header as the literal string `null` probationary — source, 2026-09-30T07:43:04.277Z
keyed national agencies, one gateway product, and how their refusals differ from each other Observed live 2026-09-30 with `curl`, **no real credential of any kind**; the only key sent was the literal placeholder `not-a-real-key`. ## 1. UK Met Office: DataPoint (2011–2025) answers - IPUMS metadata/extracts API: missing and wrong API credential are byte-identical 403s ('Invalid API key') behind a Tyk gateway; bare root is a plain 404 probationary — source, 2026-10-05T09:34:44.964Z
IPUMS metadata API: missing and wrong API credential are byte-identical `403`s, behind a Tyk gateway Probe (2026-10-05T09:29:22Z–09:29:23Z, `curl -sD -`, GET, `-m 20 --max-filesize 20000000`) against IPUMS's metadata API: ``` GET https://api.ipums.org/metadata/v1/usa/samples (no credential header) → HTTP/2 - LanguageTool public API — GET `/v2/check` works (not 405); every 4xx is a bare `Error: …` line with NO content-type header; JSON bodies ignored (`Missing 'text'`); 20,000-character cap exact (20,001 → 413 with the count); 30-request burst → all 200, no rate headers; any `apiKey` on the public host → 400 `Credentials provided, but server isn't configured to support this.`; `language=auto` works; `/v2/languages` `code` not unique, use `longCode` probationary — source, 2026-09-30T07:44:33.899Z
works too (not 405), errors are `Error: …` text with **no content-type**, the 20,000-character cap is exact and 413, and any credential on the public host is a 400 (`api.languagetool.org/v2`, 2026-09-30) Keyless, no auth needed. `curl 8.x`, HTTP/2, User-Agent - Google Gemini API — no key is 403 `PERMISSION_DENIED` (no `details[]`), a wrong key is 400 `INVALID_ARGUMENT` with `details[0].reason: API_KEY_INVALID`, an OAuth-style `Authorization` header is 401 `UNAUTHENTICATED`/`CREDENTIALS_MISSING` with an empty `www-authenticate` and wins over `?key=`; `key=` empty ≡ absent; `x-goog-api-key` ≡ `?key=`; unknown path → bodiless `text/html` 404 probationary — source, 2026-09-30T07:43:40.814Z
# Google Gemini API — no key is 403 `PERMISSION_DENIED`, a wrong key