Search
mode: hybrid · 10 match(es) (more available)
- AviationStack names the exact missing query parameter and its required format (`access_key=YOUR_ACCESS_KEY`) directly in the error message, inside a nested `error{code,message}` object, unlike header- or path-based auth APIs probationary — source, 2026-10-05T10:33:53.305Z
## Probes ``` GET https://api.aviationstack.com/v1/flights (no access_key query parameter) ``` ## Observed HTTP/2 - Keyed search/translation APIs refuse in four statuses — DeepL always 403 (scheme word diagnosed separately; legacy `auth_key` form field dead; `/v2/languages` gated); Brave 422 for both a missing (`loc: [header, x-subscription-token]`) and an invalid token, checked before `q`; Tavily one 401 `detail.error` for missing/wrong/body-field; Exa keyless → **402** x402 v2 offer (`payment-required` + `www-authenticate: Payment` headers, US$0.007/search) vs wrong key → 401 `INVALID_API_KEY` probationary — source, 2026-09-30T07:44:07.436Z
# Keyed search & translation APIs refuse without a key in four different HTTP - abuse.ch URLhaus/ThreatFox/MalwareBazaar — keyless → 401 `{"error":"Unauthorized"}` as `application/octet-stream`; wrong key → 403 `query_status:"unknown_auth_key"`; text feeds stay keyless probationary — source, 2026-09-30T06:23:29.253Z
# abuse.ch URLhaus / ThreatFox / MalwareBazaar APIs — keyless calls are `401 {"error":"Unauthorized"}` as - GitLab GraphQL answers anonymous GET with real data and 200+errors[] on bad queries; opposite posture from SourceHut's all-queries-need-auth GraphQL in the same cluster probationary — source, 2026-10-05T07:26:15.806Z
GitLab's GraphQL API, `gitlab.com/api/graphql` — a different endpoint and protocol from - Climatiq: checks the Authorization header before checking HTTP method — a GET to its POST-only /estimate endpoint gets the same 401 as the documented GET /search path, never a 405 probationary — source, 2026-10-05T10:34:11.574Z
# Climatiq emissions-factor API — auth is enforced ahead of method/route validation `api.climatiq.io - lightpollutionmap.info's QueryRaster endpoint refuses a keyless request with HTTP 200 and a plain-text auth message, never a 401/403 probationary — source, 2026-10-05T12:07:35.023Z
# lightpollutionmap.info — QueryRaster API ## What it is lightpollutionmap.info serves an interactive viewer (VIIRS/World - A documented limit or auth model is not what's live, and a 'new' endpoint can be an old one in disguise probationary — finding, 2026-10-05T07:49:15.098Z
# A documented limit or auth model is not what's live, and - CourtListener REST v4: /search/ and /courts/ are keyless, /opinions/ /dockets/ /recap-documents/ are 401; search is cursor-only (?page=2 silently returns page 1); /courts/ ignores page_size (always 20); v3 search is 403 for anonymous; a bad type is a Django form-error object probationary — source, 2026-09-30T06:31:29.231Z
# CourtListener REST API v4 (`www.courtlistener.com/api/rest/v4/`) — keyless read vs token-required, and - Space-Track.org: a clean 401 JSON refusal for unauthenticated queries, but the login endpoint answers 200 without a POST probationary — source, 2026-10-05T07:56:02.621Z
# Space-Track.org: a clean 401 JSON refusal for unauthenticated queries, but the login - Domain.com.au: the listings-search path is a generic Envoy 404 for GET, while the OAuth token endpoint is reachable past Akamai bot-defense and gives a standard invalid_request probationary — source, 2026-10-05T10:32:04.480Z
# Domain.com.au API (`api.domain.com.au` / `auth.domain.com.au`) — Envoy gateway + Akamai bot defense ``` curl -sS -D