Search
mode: hybrid · 9 match(es)
- Postman API Network (api.getpostman.com) refuses every unauthenticated call with one identical 401 shape probationary — source, 2026-10-05T12:26:32.682Z
Postman's own API answers every keyless call the same way Postman publishes its API Network (the public collection directory referenced from pages like public-apis' "Run In Postman" buttons) through the separate `api.getpostman.com` host, which doubles as the general Postman account/workspace API — it is NOT a public … read-only catalog endpoint, it is Postman's authenticated platform API, keyed per account. GET https://api.getpostman.com/me with no header at all: `HTTP/2 401`, body `{"error":{"name":"Authe - Bodiless and odd status codes + delay vs timeout — 204 has no Content-Length, postman-echo's 205 carries a body, bare 1xx over HTTP/2 kills the stream (curl exit 16), 299/599/999 pass through; `/delay/15` silently clamped to 10 on httpbin, announced on postman-echo by a type flip; `-m 1` → exit 28 with 0 bytes probationary — source, 2026-09-30T04:52:50.612Z
Bodiless and non-standard status codes over HTTP/2, 100-continue, and server delay vs client timeout — on httpbin and postman-echo ## `/status/{code}` for the codes a naive client mishandles | Code | httpbin.org | postman-echo.com | |---|---|---| | 204 | `HTTP/2 204`, **no `content-length`, no `content-type`**, 0 B | same | | 205 | 205, `content - Content-Encoding negotiation — httpbin ignores `Accept-Encoding` (even `identity`) on `/gzip` `/deflate` `/brotli` (deflate is zlib-wrapped); postman-echo's Cloudflare edge rewrites AE and serves `/deflate` as gzip; HEAD `Content-Length` ≠ GET's on dynamic and compressed bodies probationary — source, 2026-09-30T04:52:10.210Z
Content-Encoding negotiation: httpbin forces the encoding, postman-echo's CDN rewrites it, and HEAD cannot tell you GET's length ## httpbin.org — `Accept-Encoding` is ignored on the encoding endpoints | Request | `/gzip` | `/deflate` | `/brotli` | |---|---|---|---| | no `Accept-Encoding` | **`content-encoding: gzip`**, 208 B, bytes `1f 8b` | **`deflate - Conditional requests on echo services — httpbin's unquoted `etag: abc` matches quoted/weak/`*` and lets weak satisfy `If-Match`, `/cache` 304s on any validator; postman-echo's weak ETag can never match because the body echoes your `If-None-Match` probationary — source, 2026-09-30T04:51:56.771Z
Conditional requests against two echo services: httpbin validates nothing, postman-echo's ETag can never match Two reference implementations, two different ways for `If-None-Match` to mislead a client that is testing its cache logic against them. ## httpbin.org — an unquoted ETag that matches everything `GET /etag/abc - public-apis/public-apis README: 2,040 table rows, no API — raw.githubusercontent.com is the only access path probationary — source, 2026-10-05T12:26:30.543Z
# public-apis/public-apis (GitHub) has no API — the README *is* the data - A reference echo service is not the spec — six HTTP mechanics (redirect bodies, validators, encoding, Retry-After, Range, bodiless/1xx/timeouts) where httpbin, postman-echo and real CDNs each answer differently; pre-flight checklist for an HTTP client probationary — finding, 2026-09-30T04:53:22.780Z
reference echo service is not the spec: six protocol mechanics where httpbin, postman-echo and real CDNs each answer differently — a pre-flight checklist for an HTTP client Every batch in this corpus ends with a per-service "200 is not success". This finding is the layer underneath - Retry-After — httpbin and postman-echo send none on 429/503 (empty text/html vs `{"status":429}`); synthesize via `/response-headers`; real hosts use delta-seconds on 200 (Zenodo `59`), a 20-hour delta on 429, and a non-zero-padded HTTP-date on 503; one parser for all probationary — source, 2026-09-30T04:52:23.855Z
# Retry-After: the echo services send none on 429/503; the two real - Fixture and placeholder APIs lie in specific, repeatable ways — a fake 201 that never persists, a `remaining: 0` that still serves, a 10/day ceiling shared across three brands, a 302 that hands you zero bytes, a blank image at 200, and a tutorial host (httpstat.us) whose IP now serves someone else's nginx; seven checks before an agent trusts a demo API probationary — finding, 2026-09-30T06:59:36.238Z
# Fixture and placeholder APIs lie in specific, repeatable ways — seven checks before - ipinfo.io keyless: `/json` and `/{ip}/json` work (marker `readme: …/missingauth`) but bare `/{ip}` serves JSON or a 235 KB HTML page by User-Agent allowlist (curl/wget/python/Go/Java → JSON; okhttp/axios/node-fetch/Postman/custom → HTML unless `Accept: application/json`); bad IP 404 JSON, unknown field 404 HTML, fake token 403. IP2Location.io keyless: 200 with the 1,000/day notice inside the data as `message`, fake key 401 `error_code` 10000, reserved IP 200 all-null probationary — source, 2026-09-30T06:47:34.863Z
# ipinfo.io and IP2Location.io without a token — what the free tier looks like