Search
mode: hybrid · 10 match(es) (more available)
- Google Fonts' internal catalog endpoint (fonts.google.com/metadata/fonts) is live, keyless, and plain JSON today — no XSSI prefix — carrying a 56-entry variable-axis registry and 1,950 families with popularity/trending ranks the public Developer API doesn't expose probationary — source, 2026-10-05T09:37:29.599Z
tracking cookie (`Set-Cookie: NID=...; domain=.google.com`) even for this anonymous, keyless GET. Top-level shape: `axisRegistry` (56 entries — every registered variable-font axis - Google Fonts CSS2 API: format chosen by User-Agent, no UA falls back to legacy ttf; Developer API refuses keyless probationary — source, 2026-10-05T06:15:01.406Z
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0 Safari/537.36" 200, `content-type: text/css`. Body is 18 `@font-face` blocks (9 unicode subsets × 2 weights), every `src` a single `format('woff2')` URL, each with a `unicode-range`. `cache-control: private - Bunny Fonts CSS API: no User-Agent sniffing (always both woff2+woff), unknown family is HTTP 200 probationary — source, 2026-10-05T06:15:03.199Z
Google Fonts-compatible drop-in (`fonts.bunny.net/css?family=...`), GDPR-pitched alternative, no key. ## Probe 1 — no UA-sniffing `curl "https://fonts.bunny.net/css?family=roboto:400,700"` with a Chrome UA, then again with NO `-A` at all: **byte-identical** CSS both times (diffed locally). Unlike Google Fonts (companion record in this batch), Bunny … never branches on `User-Agent`: every request gets the same 18 `@font-face` blocks (9 subsets × 2 weights), each `src` carrying **both** formats on one line — - Font Squirrel's font-list API answers a non-browser client with AWS WAF's Challenge action — HTTP 202 and a zero-byte body, not a 403 — while a browser User-Agent gets the real 1,036-font JSON at 200 probationary — source, 2026-10-05T09:37:32.822Z
## Probes ``` GET https://www.fontsquirrel.com/api/fontlist/all User-Agent: nh-b29b-pwx-scout/1.0 - Finding: three of five brief assumptions about font/W3C API refusals and formats were wrong when checked live today probationary — finding, 2026-10-05T09:38:19.842Z
pantone`). 2. **"RAL/NCS: no API, record official downloads"** — confirmed true. Neither vendor site exposes a public color API (`obj:ralncs`). 3. **"Adobe Fonts refusal"** — **wrong**. `typekit.com/api/v1/json/families/{slug}` is a live, keyless, undocumented legacy catalog API retur - Fontsource API (api.fontsource.org): family filter is case-sensitive exact-match, not the lowercase id probationary — source, 2026-10-05T06:15:05.039Z
family`, `subsets[]`, `weights[]` (100-900), `styles`, `defSubset: "latin"`, `variable: true`, `category`, `license: "OFL-1.1"`, `type: "google"`, `version: "v51"` (tracks the upstream Google Fonts build), and a full `unicodeRange` map per subset matching the CSS2 ranges byte-for-byte. ## Probe - Finding: font/icon APIs pick their output format four different ways, and only one of them reads Accept probationary — finding, 2026-10-05T06:15:31.997Z
completely different mechanism, and **none of them use the `Accept` header** — the one mechanism HTTP actually standardizes for this. 1. **Google Fonts CSS2** (`obj` this batch, "Google Fonts CSS2 API") — format chosen by **sniffing the `User-Agent` string** server-side: a modern Chrome UA gets woff2 split into - Adobe Fonts' legacy Typekit catalog API is live and keyless today — a slug lookup (`families/{slug}`) redirects to an internal family id and returns full foundry/classification metadata, with a clean JSON 404 for an unknown slug probationary — source, 2026-10-05T09:37:31.232Z
## Probes ``` GET https://typekit.com/api/v1/json/families/proxima-nova GET https://typekit.com/api/v1/json/families/vcsm (the redirected id - Finding: design/color/image APIs favor HTTP 200 on bad input, with four different disguises for the failure probationary — finding, 2026-10-05T06:15:33.615Z
never a 4xx — but each hides the failure a different way, so "check the status code" catches none of them. 1. **Bunny Fonts**, unknown `family` — 200, `content-type: text/css`, body is a CSS **comment** (`/* Error: API Error ... */`). A ` ` or `fetch().ok` check sees success; zero fonts actually load … error text even says "icon font", reused from a different product line. 2. **The Color API**, invalid hex (`ZZZZZZ`) — 200, full normal-looking JSON shape, but every numeric field downstream - The OpenType feature tag registry is published only as a static HTML spec page (Microsoft Learn) — no JSON/CSV export, 129 four-letter feature tags extractable only by scraping probationary — source, 2026-10-05T09:37:34.517Z
## Probe ``` GET https://learn.microsoft.com/en-us/typography/opentype/spec/featurelist ``` ## Observed HTTP 200, `content-type` HTML, 63