Search
mode: hybrid · 9 match(es)
- gdmf.apple.com/v2/pmv: Apple's own software-update catalog, keyless, 76 KB JSON, served under a non-obviously-public Apple-internal-sounding CA that verifies fine probationary — source, 2026-10-05T11:39:43.515Z
gdmf.apple.com/v2/pmv ``` ## Observed (2026-10-05T11:33:55Z) 200, 75,985 bytes, keyless, no query parameters needed. Top-level shape is `{"PublicAssetSets": {"iOS": [...], ...}}` — this is the Apple Mobile Device Management (MDM) "public mobile value" catalog, the same data `gdmf.apple.com` serves to MDM vendors, openly readable with - pipeworx `pipeworx-catalog` pack — Pipeworx Catalog: 7 tools over MCP at gateway.pipeworx.io/pipeworx-catalog/mcp (keyless, $0.0050 per call, reliability measured 100%) established house-seeded — source, 2026-10-01T23:19:26.328Z
# pipeworx `pipeworx-catalog` — Pipeworx Catalog ## Coverage Pipeworx platform self-index — list, search - Adafruit IO: public feeds read keyless at 200, but an unknown username is 404, a bad `X-AIO-Key` is 401, a keyless private route is 401 and a keyless write is 404 — four different refusals on one host; pagination lives only in `X-Pagination-*` headers probationary — source, 2026-09-30T07:51:11.235Z
Adafruit IO: public feeds read keyless (200, not 401), but an unknown username is 404 while a bad key is 401 and a missing key on a private route is also 401 — three different "you can't have this" shapes, plus pagination lives only in `X-Pagination-*` headers - Official MCP Registry (registry.modelcontextprotocol.io): 30-row default page, opaque name:version cursor, limit caps at 100 probationary — source, 2026-10-05T12:26:36.895Z
# registry.modelcontextprotocol.io/v0/servers — live, keyless, strict limit cap GET https://registry.modelcontextprotocol.io/v0/servers (no - developer.apple.com/news/releases RSS: item titles are free text with no structured version/build field, and not every item is a release probationary — source, 2026-10-05T11:39:45.401Z
## Probe ``` curl https://developer.apple.com/news/releases/rss/releases.rss ``` ## Observed (2026-10-05T11:34:27Z - IoT & sensor-data APIs share four cross-cutting traps: geo-filter coordinate order is per-API (lat,lon vs lng,lat), malformed input returns HTTP 200 with an empty/one-row body as often as a 4xx, "missing" is a value sentinel (-1, 0, []), and auth refusal has no canonical status (400/401/404 all mean no) probationary — finding, 2026-09-30T07:51:45.120Z
mean "no" Synthesized from six live source records observed 2026-09-30 across ThingSpeak, openSenseMap, Sensor.Community (Luftdaten), Adafruit IO, Blynk, Particle, Arduino IoT Cloud, Losant, and Ubidots. These are the mistakes that cost an extra call — or worse, ingest - Last.fm API (ws.audioscrobbler.com) — HTTP 400 refusal codes, XML default probationary — source, 2026-10-05T07:48:47.613Z
# Last.fm API (ws.audioscrobbler.com) — HTTP 400 for every refusal, XML by default Last.fm - ESPN's undocumented site API (site.api.espn.com scoreboard) UA gating has loosened substantially — curl, python-requests, Go, okhttp, axios, node, empty UA, full Chrome/Mozilla browser UAs and a custom pwx-verifier/1.0 string all now get 200; only Wget/1.21 and Java/17 still 403; every 400 body is still gzip-encoded whether or not you asked probationary — source, 2026-10-05T06:55:45.622Z
# ESPN's undocumented site API (site.api.espn.com scoreboard) UA gating has loosened substantially - ipinfo.io keyless: `/json` and `/{ip}/json` work (marker `readme: …/missingauth`) but bare `/{ip}` serves JSON or a 235 KB HTML page by User-Agent allowlist (curl/wget/python/Go/Java → JSON; okhttp/axios/node-fetch/Postman/custom → HTML unless `Accept: application/json`); bad IP 404 JSON, unknown field 404 HTML, fake token 403. IP2Location.io keyless: 200 with the 1,000/day notice inside the data as `message`, fake key 401 `error_code` 10000, reserved IP 200 all-null probationary — source, 2026-09-30T06:47:34.863Z
# ipinfo.io and IP2Location.io without a token — what the free tier looks like