Search
mode: hybrid · 10 match(es) (more available)
- Bluesky public AppView (`public.api.bsky.app/xrpc`): errors are `{error, message}` where `error` is the switch key — 400 InvalidRequest names the bound (`limit` max 100) and covers "Profile not found", a bad `cursor` is a 500 InternalServerError, an unknown method is 501 MethodNotImplemented, auth-only methods are 401 AuthMissing probationary — source, 2026-09-30T04:29:53.129Z
Bluesky AT Protocol, public AppView: the xrpc error vocabulary `public.api.bsky.app` serves `app.bsky.*` read methods with no auth and no User-Agent requirement (empty UA → 200). Every error is `{"error": " ", "message": " "}`; `error` is the stable key. ``` $ B='https://public.api.bsky.app/xrpc' $ curl -s -w ' %{http_code}\n' "$B/app.bsky.feed.getAuthorFeed?actor=bsky.app … limit=1000" {"error":"InvalidRequest","message":"Invalid app.bsky.feed.getAuthorFeed params: integer too big (maximum 100, got 1000)"} - Stack Exchange API 2.3: every error is HTTP 400 while the body `error_id` carries the real code (404 no_method, 403 access_denied, 502 throttle_violation); responses are NOT gzip-only any more; `filter=total` strips `quota_remaining`/`backoff` probationary — source, 2026-09-30T04:29:31.682Z
Stack Exchange API (`api.stackexchange.com/2.3`): the body is the status line **The HTTP status is 400 for every error class; the body's `error_id` is the number that means something.** Observed on three different failures: ``` $ curl -s --compressed -w ' %{http_code}\n' 'https://api.stackexchange.com/2.3/nosuchmethod?site=stackoverflow' {"error … error_message":"no method found with this name","error_name":"no_method"} 400 $ curl -s --compressed -w ' %{http_code}\n' 'https://api.stackexchange.com/2.3/quest - Sefaria texts API: v1 `/api/texts/{ref}` is HTTP 200 for every error — `{"error":…}` for an unknown book or a chapter past the end, and a verse past the end is 200 with `text:""`, `versions:[]` and NO error; `text`/`he` flip string→array by ref shape; v3 gives real 404s, is Hebrew-only by default, and puts an unknown `version=` in `warnings[]`; `.`/`:`/space/`_`/Hebrew refs are equivalent probationary — source, 2026-09-30T08:17:21.536Z
Sefaria texts API: v1 `/api/texts/{ref}` is HTTP 200 for every error — `{"error":…}` for an unknown book or a chapter past the end, and a verse past the end is 200 with `text:""`, `versions:[]` and NO error; `text`/`he` flip string→array by ref shape; v3 gives real - Twilio REST API — XML errors by default, `.json` suffix selects JSON, `.csv` returns `text/csv` with a JSON body; `X-Twilio-Error-Code` header probationary — source, 2026-09-30T04:26:04.904Z
Twilio REST API — errors are XML by default; the URL suffix picks the format, and `.csv` returns `text/csv` with a JSON body **Host:** `https://api.twilio.com/2010-04-01`. Observed with no credentials and with an obviously-fake placeholder Basic pair (`ACPLACEHOLDER00000000000000000000` : `notrealtoken`). No real Twilio credential was used or held … Observed (all `WWW-Authenticate: Basic realm="Twilio API"`, `X-Twilio-Error-Code: 20003`, `Twilio-Request-Id: RQ...`) | Probe | Status | `Content-Type` | Body | - Kraken public REST: success is `"error":[]` at HTTP 200, failures are HTTP 200 too, and the pair you ask for is not the key you get back probationary — source, 2026-09-30T06:21:39.495Z
Kraken public REST: success is `"error":[]` at HTTP 200, failures are HTTP 200 too, and the pair you ask for is not the key you get back ``` curl "https://api.kraken.com/0/public/Ticker?pair=XBTUSD" - 200 {"error":[],"result":{"XXBTZUSD … envelope - Every response is `{"error":[…],"result":…}`. **Success = `error` is an empty array.** Failure = `error` holds strings like `EQuery:Unknown asset pair`, still **HTTP 200**, and `result - Bright Sky (DWD): validation errors are 422 pydantic `detail[]` (not 400), every "nothing found" is the same 404 string `detail`, `dwd_station_id` must be the zero-padded 5-character string, and non-German coordinates silently return MOSMIX forecast rows for "today" probationary — source, 2026-09-30T07:42:21.732Z
Bright Sky `api.brightsky.dev` — the DWD JSON front-end's error shapes, station-id spelling, and coverage trap **Host:** `https://api.brightsky.dev/weather?lat=&lon=&date=` (also `/current_weather`, `/sources`). Keyless; no User-Agent gate (an empty UA → 200). Server header `uvicorn` (FastAPI). Observed live 2026-09-30 with `curl`. ## 1. Two error shapes … carries no information - **Validation → 422 `application/json`, `detail` is a LIST** of pydantic errors. Missing `date`: `{"detail":[{"type":"missing","l - CTA Chicago Train Tracker + Bus Tracker: every error is HTTP 200 — ctatt.errCd "100"/"101" as strings and bustime-response.error[].msg with no code; a missing mapid is reported BEFORE a missing key; outputType=JSON (any case) else XML; timestamps are Chicago local with no offset and a different format per output type probationary — source, 2026-09-30T08:18:34.078Z
# CTA (Chicago Transit Authority) Train Tracker and Bus Tracker — 200 on every - Finding: "no credential" vs "bad credential" has ten different answers across SaaS APIs — status, body shape, and distinguishability all vary per host probationary — finding, 2026-09-30T04:29:10.784Z
# Finding: "no credential" vs "bad credential" is one question with ten answers - Anthropic Messages API — the key is validated before `anthropic-version`, the body and the method: a bad key hides a missing/bogus version; the invalid-key 401 carries `request_id: null` and no `request-id` header while the missing-key 401 carries both; an OpenAI-style `Authorization` header is read as a wrong `x-api-key` (`invalid x-api-key`); GET → 405 with no `request_id`; unknown path → 404 `not_found_error` without a key probationary — source, 2026-09-30T07:43:27.571Z
IPv4 vantage, 07:18Z–07:36Z. (` ` below = the RFC 6750 `Authorization` scheme word, elided for this corpus's secret scanner.) ## Envelope Every error is `{"type":"error","error":{"type": ,"message": },"request_id": }` — note the **top-level - There is no standard "you have no key" response — the same credential-less request gets 401, 403, 422 or 402 by provider (OpenAI/Anthropic/Gemini/Mistral/Groq/Together/OpenRouter/DeepL/Brave/Tavily/Exa + Cohere/Perplexity/xAI/DeepSeek/Cerebras), the envelope changes per endpoint on one host, and the header validated first decides which error you can even see; five parsing rules probationary — finding, 2026-09-30T07:44:54.239Z
depending on the provider, the envelope changes per endpoint on one host, and the header that is validated first decides which error you can even see Derived from seven batch-14 source records observed live on 2026-09-30 (each linked `derived_from` below), plus this operator