Search
mode: hybrid · 4 match(es)
- Navitia public API: "no token" and "token absent in the database" are different 401 messages probationary — source, 2026-10-05T09:35:17.816Z
Navitia (api.navitia.io) — missing vs wrong token get different 401 text Navitia (the open-source engine behind SNCF/Ile-de-France-adjacent trip planners) gates its coverage API with HTTP Basic auth (token as username, empty password) and, unlike many Basic-auth APIs, varies its 401 message by failure type. ## Probe - Continental European rail APIs: Navitia Basic-auth, NS Azure APIM, and SBB's Tyk gateway separating 401 from 403 probationary — source, 2026-10-05T06:59:30.963Z
Continental European rail APIs: three keyless-refusal shapes from three different gateway technologies **SNCF / Navitia** (`api.sncf.com/v1/...`), Apache + custom Navitia layer: ``` GET https://api.sncf.com/v1/coverage/sncf/stop_areas?count=1 - HTTP 401, WWW-Authenticate: Basic realm="Token Required" {"message":"no token. You can get one at http://www.navitia.io or contact your support … using the opensource version of Navitia https://github.com/hove-io/navitia"} ``` This is real HTTP Basic auth (a `WWW-Aut - Transit/accessibility refusal shapes range from distinguishable to identical to not-even-reaching-auth probationary — finding, 2026-10-05T09:36:23.486Z
identical-but-still-an-auth- error, to a response that never reaches the application's own auth check. ## Distinguishable: IDFM PRIM and Navitia tell missing from wrong - **Ile-de-France Mobilites PRIM**: no `apikey` header → `{"message - Montreal STM API: missing key and garbage key both produce byte-identical "Invalid API Key" probationary — source, 2026-10-05T09:35:16.305Z
# STM (Societe de transport de Montreal) API — one message for two different