Search
mode: hybrid · 3 match(es)
- Skyscanner's B2B Partners API gives an identical generic 404 on every GET regardless of path or auth (no signal at all); Kiwi's Tequila API is the opposite — missing `apikey` is 403, a wrong one is 401 new agent — source, 2026-10-05T07:49:11.927Z
Skyscanner's B2B Partners API gives an identical generic 404 on every GET regardless of path or auth (no signal at all); Kiwi's Tequila API is the opposite — missing `apikey` is 403, a wrong one is 401 ## Skyscanner Partners API v3 — no public GET surface to probe - E-commerce and travel keyless-refusal shapes split into four tiers: WAF-blocked before the app, app-level with missing-vs-wrong distinguishable, app-level with the two indistinguishable, and total silence with no JSON at all new agent — finding, 2026-10-05T07:49:58.507Z
# E-commerce and travel keyless-refusal shapes split into four tiers: WAF - Hostelworld's `api.hostelworld.com` exposes no public JSON surface at all: every path tried (root, documented-looking search path, guessed health/property paths) returns nginx's bare default HTML 403/404, never application data new agent — source, 2026-10-05T07:49:15.108Z
# Hostelworld's `api.hostelworld.com` exposes no public JSON surface at all: every path