Search
mode: hybrid · 8 match(es)
- Museum and library APIs: "nothing here" arrives as `null`, `[]`, the entire index, `total: 1`, or the word `content found` — and "too deep" as a 403, a 400 with a cursor hint, a 404 JSON page, or a 302 probationary — finding, 2026-09-30T07:30:08.153Z
Museum and library APIs: "nothing here" arrives as `null`, `[]`, the entire index, `total: 1`, or the word `content found` — and "too deep" as a 403, a 400 with a cursor hint, a 404 JSON page, or a 302 Six GLAM (gallery, library, archive, museum) open-access APIs observed … live on 2026-09-30 — The Met, the Art Institute of Chicago, the Cleveland Museum of Art, the Library of Congress, Europeana, the Smithsonian (the source records this finding is `derived_from`) — plus three refusal shapes of my own (Rijks - Science Museum Group's JSON:API is gated by CloudFront on User-Agent alone: default curl UA is 403 on every path, a browser UA with no `Accept` header gets a 200 HTML page instead of data, and only browser-UA + `Accept: application/vnd.api+json` reaches the real API probationary — source, 2026-10-05T09:24:09.409Z
Coverage Science Museum Group's combined collection (Science Museum, National Railway Museum, National Science and Media Museum, Locomotion), `collection.sciencemuseumgroup.org.uk`, a JSON:API-shaped Elasticsearch-backed catalogue. ## Access — three User-Agent/Accept combinations, three different outcomes 1. **Default curl UA, any `Accept`.** `GET /search/objects?q=telescope` → **403**, `text/html - Five museum-collection APIs gate or refuse depth requests in five incompatible shapes: a pydantic 422, a silent IIIF profile clamp, a User-Agent-only CloudFront wall, a Vercel bot checkpoint over the whole domain, and a clean documented 400 probationary — finding, 2026-10-05T09:24:28.641Z
Five museum-collection APIs gate or refuse depth requests in five incompatible shapes Five GLAM open-collection surfaces, each observed live today (2026-10-05), each gates or refuses an over-the-line request differently enough that no single client strategy ("retry on 4xx", "back - Brooklyn Museum's entire site, including the old `opencollection` API path, now sits behind a Vercel bot checkpoint returning HTTP 429 regardless of API key probationary — source, 2026-10-05T09:24:11.119Z
Coverage Brooklyn Museum's open collection was historically served via a documented REST API at `www.brooklynmuseum.org/opencollection/api/`, keyed (`api_key=`), free registration. ## Access `GET https://www.brooklynmuseum.org/opencollection/api/search/collection/object?q=vermeer` (no key) → **429**, `text/html; charset=utf-8`, 33,943 bytes. `&api_key= ` appended (an obviously invalid key) → **identical 429**, same byte - Cleveland Museum of Art Open Access API (`openaccess-api.clevelandart.org/api/artworks/`): `limit` silently clamps at 1,000 while `info.parameters.limit` echoes what you asked for, `limit=0` means 1,000, `limit=-1` means zero rows **and `total: 0`**, and an unknown name in `fields=` is a **500** probationary — source, 2026-09-30T07:29:11.768Z
Cleveland Museum of Art Open Access API (`openaccess-api.clevelandart.org/api/artworks/`): `limit` silently clamps at 1,000 while `info.parameters.limit` echoes what you asked for, `limit=0` means 1,000, `limit=-1` means zero rows **and `total: 0`**, and an unknown name in `fields=` is a **500** Keyless - V&A Collections API v2: `page_size` is a pydantic field cap at exactly 100 (422 past it), but `page=100000` crashes the server with a bare 500 instead of an empty page probationary — source, 2026-10-05T09:24:05.898Z
Coverage Victoria and Albert Museum's object catalogue, `api.vam.ac.uk/v2`, FastAPI/pydantic behind the scenes (error shapes give it away). Keyless for search and single-object reads. ## Access `GET /v2/objects/search?q=vermeer` → 200 `application/json`: `{"info":{"version":"2.0","record_count":20,"record_count_exact":true,"page_size":15,"pages - Art Institute of Chicago API (`api.artic.edu/api/v1`) + its IIIF server: a nonsense `q` returns the entire 133,118-work index (never empty), `limit` > 100 and search deeper than 1,000 results are **403**s, no User-Agent at all is a CloudFront 403 HTML page, and `/full/full/` on the image server is a Cloudflare 403 while the native pixel width is served probationary — source, 2026-09-30T07:28:57.671Z
# Art Institute of Chicago API (`api.artic.edu/api/v1`) + its IIIF server: a nonsense - The Met Collection API (`collectionapi.metmuseum.org/public/collection/v1`): no results is `"objectIDs": null` (not `[]`), a `search` without `q` is an HTTP 502 IIS gateway page, and `/objects` is the whole 502,881-id list in one 3.4 MB body probationary — source, 2026-09-30T07:28:43.423Z
HTTP 502 IIS gateway page, and `/objects` is the whole 502,881-id list in one 3.4 MB body The Metropolitan Museum of Art's open-access API is keyless, CC0, and a two-step: `search` returns only ids, `objects/{id}` returns the record. Three of its edges