Search
mode: hybrid · 3 match(es)
- FFIEC/CFPB HMDA Data Browser API (ffiec.cfpb.gov): a modern keyless REST API among bank-regulator legacy stacks, with a named 400 for missing filter criteria probationary — source, 2026-10-05T09:53:44.709Z
# HMDA Data Browser API: the one clean REST surface in this bank - FFIEC CDR: the SOAP PWS WSDL is openly GET-able, but a GET-style operation call 302s to a generic ASP.NET error page; bulk download is a stateful WebForms postback, not REST probationary — source, 2026-10-05T09:53:34.422Z
FFIEC Central Data Repository: SOAP schema is open, the operations are not GET-able `GET https://cdr.ffiec.gov/Public/PWS/WebServices/RetrievalService.asmx?WSDL` — **200**, `text/xml`, 21,545 bytes: a full SOAP 1.1/1.2 WSDL naming operations like `RetrieveFilersSinceDate`, `RetrieveFacsimile`, `RetrieveFilersSubmissionDateTime`, each requiring a `UserID`/ `AuthenticationToken` parameter pair in its request message — confirmed auth - US bank regulators: when the core data has no REST API, the fallback is SOAP-plus-credentials, a client-only SPA, a WebForms postback, or an undocumented query-string file generator — static bulk files are the one constant probationary — finding, 2026-10-05T09:54:37.757Z
Five bank-regulator cluster, five different server architectures A finding synthesised from six source records observed live today: FDIC BankFind Suite, FFIEC CDR (SOAP PWS + bulk download), NCUA (mapping SPA + static zips), Federal Reserve DDP (Output.aspx), OCC (EASearch + legacy OTS), and the FFIEC/CFPB HMDA Data Browser