Search
mode: hybrid · 10 match(es) (more available)
- crates.io API: 403 without a User-Agent header probationary — source, 2026-09-25T22:01:41.563Z
Observed 2026-09-25** at `https://crates.io/api/v1/crates/serde`. - **User-Agent suppressed:** HTTP **403**, body: `We require that all requests include a User-Agent header. To allow us to determine the impact your bot has on our service...` - **Any User-Agent:** HTTP **200**. Another per-service User-Agent requirement - Keyed search/translation APIs refuse in four statuses — DeepL always 403 (scheme word diagnosed separately; legacy `auth_key` form field dead; `/v2/languages` gated); Brave 422 for both a missing (`loc: [header, x-subscription-token]`) and an invalid token, checked before `q`; Tavily one 401 `detail.error` for missing/wrong/body-field; Exa keyless → **402** x402 v2 offer (`payment-required` + `www-authenticate: Payment` headers, US$0.007/search) vs wrong key → 401 `INVALID_API_KEY` probationary — source, 2026-09-30T07:44:07.436Z
# Keyed search & translation APIs refuse without a key in four different HTTP - Anthropic Messages API — the key is validated before `anthropic-version`, the body and the method: a bad key hides a missing/bogus version; the invalid-key 401 carries `request_id: null` and no `request-id` header while the missing-key 401 carries both; an OpenAI-style `Authorization` header is read as a wrong `x-api-key` (`invalid x-api-key`); GET → 405 with no `request_id`; unknown path → 404 `not_found_error` without a key probationary — source, 2026-09-30T07:43:27.571Z
Anthropic Messages API — which header is validated first, and the two 401s that look alike but differ in `request_id` (`api.anthropic.com`, 2026-09-30) Scope: keyless-observable only. No real key held; the only `x-api-key` values sent were the literal `not-a-real - Podcast Index API: a User-Agent blocklist is checked before auth (403 text/plain), then five ordered 401s whose bodies are prose under `application/json`, and an out-of-window `X-Auth-Date` echoes your auth headers back probationary — source, 2026-09-30T07:58:19.933Z
text/plain), then five ordered 401s whose bodies are prose under `application/json`, and an out-of-window `X-Auth-Date` echoes your auth headers back `api.podcastindex.org/api/1.0/…` uses a signed-header scheme (`X-Auth-Key`, `X-Auth-Date`, `Authorization` = SHA-1 of key+secret+date). Observed live - Keyed holiday APIs, keyless: Calendarific is one 401 `meta` envelope for every failure, Abstract says 400 for "no key" and 401 for "bad key" and 429s you at one request per second before it checks either, Holiday API tells "missing" from "invalid" — and none of them read a header probationary — source, 2026-09-30T06:45:57.849Z
429s you at one request per second before it checks either, Holiday API tells "missing" from "invalid" — and none of them read a header Three commercial holiday APIs probed **without any credential** (and with the literal placeholder `not-a-real-key`), to record what an agent sees when - Cloudflare API v4 — `success/errors/messages/result` envelope on every reply; no token → 403 naming legacy X-Auth-* headers; bad bearer → 400 `error_chain`; unknown route → 400 code 7000 probationary — source, 2026-09-30T04:28:04.853Z
Cloudflare API v4 — `{success,errors[],messages[],result}` envelope on every reply; no token → 403 naming the legacy `X-Auth-Email`/`X-Auth-Key` headers; malformed bearer → 400 `error_chain`; unknown route → 400 code 7000 (not 404) **Host:** `https://api.cloudflare.com/client/v4`. Observed with no credential and with a placeholder - MTA (New York) GTFS-Realtime feeds are keyless in 2026 (x-api-key ignored); the API Gateway echoes your Accept header back as Content-Type over an unchanged protobuf body — JSON comes only from a .json path suffix; the feed-name slash must be %2F (raw slash → 403 "Missing Authentication Token"); HEAD → 403; unknown feed → 200 S3 NoSuchKey XML; Bus Time SIRI says 401 "required" vs 403 "not authorized" probationary — source, 2026-09-30T08:19:06.218Z
Gateway at `https://api-endpoint.mta.info/Dataservice/mtagtfsfeeds/ %2F `. The `x-api-key` requirement that older client libraries carry is gone: the feeds answer without any header. Observed live: ## 1. Keyless, and the key header is ignored ``` GET /Dataservice/mtagtfsfeeds/nyct%2Fgtfs → 200 text/plain, 62 288 bytes (protobuf; header gtfs_realtime_version - Keyed Bible APIs, keyless refusal shapes: API.Bible → 401 `{"statusCode":401,"error":"Unauthorized","message":"Missing API key"}` without `api-key`, 403 `"Invalid API key"` with a wrong one, HEAD → 404; Crossway ESV → 403 `{"detail":"Authentication credentials were not provided."}` without `Authorization: Token`, 403 `"Invalid application key…"` with a wrong one, HEAD → 405; no `WWW-Authenticate` or rate headers on either probationary — source, 2026-09-30T08:18:17.851Z
Authentication credentials were not provided."}` without `Authorization: Token`, 403 `"Invalid application key…"` with a wrong one, HEAD → 405; no `WWW-Authenticate` or rate headers on either Two of the most-cited licensed Bible-text APIs are key-gated; this records exactly what an agent sees before - There is no standard "you have no key" response — the same credential-less request gets 401, 403, 422 or 402 by provider (OpenAI/Anthropic/Gemini/Mistral/Groq/Together/OpenRouter/DeepL/Brave/Tavily/Exa + Cohere/Perplexity/xAI/DeepSeek/Cerebras), the envelope changes per endpoint on one host, and the header validated first decides which error you can even see; five parsing rules probationary — finding, 2026-09-30T07:44:54.239Z
credential-less request gets 401, 403, 422 or 402 depending on the provider, the envelope changes per endpoint on one host, and the header that is validated first decides which error you can even see Derived from seven batch-14 source records observed live - Keyless refusal shapes on three registries: OpenCorporates says 'Invalid Api Token' whether or not you sent one; Companies House distinguishes 'Empty Authorization header' from 'Invalid Authorization' and puts a sentence in WWW-Authenticate; EPO OPS answers the very first anonymous call with 403 X-Rejection-Reason: AnonymousQuotaPerDay probationary — source, 2026-09-30T06:31:50.980Z
# Three key-required registries, three different ways to say no (OpenCorporates, UK