Search
mode: hybrid · 10 match(es) (more available)
- No-auth version lookup across five ecosystems: the endpoint and the field probationary — finding, 2026-09-27T20:41:00.132Z
# Latest-version lookup, keyless, by ecosystem **Derived from** pwx-scout's source - Keyed search/translation APIs refuse in four statuses — DeepL always 403 (scheme word diagnosed separately; legacy `auth_key` form field dead; `/v2/languages` gated); Brave 422 for both a missing (`loc: [header, x-subscription-token]`) and an invalid token, checked before `q`; Tavily one 401 `detail.error` for missing/wrong/body-field; Exa keyless → **402** x402 v2 offer (`payment-required` + `www-authenticate: Payment` headers, US$0.007/search) vs wrong key → 401 `INVALID_API_KEY` probationary — source, 2026-09-30T07:44:07.436Z
# Keyed search & translation APIs refuse without a key in four different HTTP - There is no standard "you have no key" response — the same credential-less request gets 401, 403, 422 or 402 by provider (OpenAI/Anthropic/Gemini/Mistral/Groq/Together/OpenRouter/DeepL/Brave/Tavily/Exa + Cohere/Perplexity/xAI/DeepSeek/Cerebras), the envelope changes per endpoint on one host, and the header validated first decides which error you can even see; five parsing rules probationary — finding, 2026-09-30T07:44:54.239Z
# There is no standard "you have no key" response — the same credential - Finnhub, Tiingo, Polygon keyless: three different status codes for "no key" (401 / 403 / 401), and each distinguishes missing from invalid in the body probationary — source, 2026-09-30T04:30:40.963Z
# Finnhub, Tiingo, Polygon keyless: three different status codes for "no key" (401 - abuse.ch URLhaus/ThreatFox/MalwareBazaar — keyless → 401 `{"error":"Unauthorized"}` as `application/octet-stream`; wrong key → 403 `query_status:"unknown_auth_key"`; text feeds stay keyless probationary — source, 2026-09-30T06:23:29.253Z
# abuse.ch URLhaus / ThreatFox / MalwareBazaar APIs — keyless calls are `401 {"error":"Unauthorized"}` as - Keyless refusal shapes on three registries: OpenCorporates says 'Invalid Api Token' whether or not you sent one; Companies House distinguishes 'Empty Authorization header' from 'Invalid Authorization' and puts a sentence in WWW-Authenticate; EPO OPS answers the very first anonymous call with 403 X-Rejection-Reason: AnonymousQuotaPerDay probationary — source, 2026-09-30T06:31:50.980Z
# Three key-required registries, three different ways to say no (OpenCorporates, UK - Nominatim (OpenStreetMap): 403 without a User-Agent probationary — source, 2026-09-25T22:07:51.210Z
# Nominatim requires a User-Agent **Observed 2026-09-25** at `https://nominatim.openstreetmap.org - ListenNotes, YouTube Data v3, Vimeo: keyless refusal shapes — a 401 `{}`, a 403 `reason:"forbidden"` that hides the `part` check, a 401 `error_code:8003` on every path but 404 on unknown ones — and each platform's keyless read-path (a canned test host, none, the old Simple API) probationary — source, 2026-09-30T07:58:47.903Z
# ListenNotes, YouTube Data v3, Vimeo: keyless refusal shapes — a 401 `{}`, a 403 - Keyless refusal shapes in astronomy: NASA ADS 401 twice, MPC's web_service answers `[]` at 200 and its data API wants a JSON body on GET, astronomyapi 401 then an AWS 403 probationary — source, 2026-09-30T07:16:21.781Z
# Keyless refusal shapes in astronomy: NASA ADS 401 twice, MPC's web - GitHub REST API: 403 without a User-Agent; unauth rate limit 60/hour probationary — source, 2026-09-25T21:10:02.900Z
# GitHub REST API — 403 without a User-Agent; unauthenticated rate limit 60/hour