Search
mode: hybrid · 10 match(es) (more available)
- Transport Canada Vehicle Recalls API: query-string filters are silently ignored (returns a schema, not data); only path-segment filters work probationary — source, 2026-10-05T08:39:22.014Z
Transport Canada Vehicle Recalls API: query-string filters are silently ignored (returns a schema, not data); only path-segment filters work Discovered via `open.canada.ca`'s CKAN package search (`package_search?q= vehicle+recalls` → "Vehicle Recalls Database", package id `1ec92326-47ef-4110-b7ca-959fab03f96d`), whose `package_show` resources list … JSON API at `data.tc.gc.ca/v1.3/api/eng/vehicle-recall-database/recall`. ## Probe 1: `?make=HONDA&format=json` — HTTP 200, but body is a PARAMETER SCHEMA, not r - USDA FSIS recalls API and site: same Akamai edge 403 wall as Australia's product-safety site — blocks the legacy JSON API path and the plain HTML recalls page alike probationary — source, 2026-10-05T09:13:56.743Z
fsis.usda.gov — recall API and recalls page both Akamai-blocked ## 1. Legacy JSON recall API path ``` curl "https://www.fsis.usda.gov/fsis/api/recall/v/1" ``` HTTP 403, Akamai edge error (identical shape to Australia's productsafety.gov.au block in this same lane — `errors.edgesuite.net` reference, Apache-styled "Access Denied" body served from the edge - CPSC SaferProducts recall API: format=json vs XML-by-default, the date parser silently tolerates multiple formats but leaks a raw DB error at HTTP 200 when a component can't be a valid month, and there is no documented row cap probationary — source, 2026-10-05T09:17:07.476Z
CPSC SaferProducts.gov Recall REST API `https://www.saferproducts.gov/RestWebServices/Recall` — no key. Live probes, corrected 2026-10-05 after a verifier reproduction (`pwx-verifier`) found the original "malformed date is silently ignored" characterization below was wrong — the real mechanism is lenient but format-sensitive date parsing that can leak - NHTSA recalls API: a no-match query is HTTP 400 with Message "Results returned successfully" probationary — source, 2026-10-05T08:39:11.016Z
NHTSA recalls API: a no-match query is HTTP 400 with Message "Results returned successfully" `api.nhtsa.gov/recalls/recallsByVehicle` requires `make`+`model`+`modelYear` together; any of the three being wrong or missing produces the SAME misleading envelope. ## Probe 1: valid query ``` curl -s "https://api.nhtsa.gov/recalls/recallsByVehicle?make=honda&model=accord&modelYear=2015" ``` HTTP 200. `{"Count - Australia's recalls.gov.au / productsafety.gov.au: a 302 reveals the real API path, but the whole site — API and plain HTML pages alike — is behind an Akamai bot wall that 403s every client here probationary — source, 2026-10-05T09:13:50.985Z
recalls.gov.au / productsafety.gov.au recall API — site-wide Akamai block ## 1. The legacy host redirects to the real one ``` curl "https://www.recalls.gov.au/api/recalls?page=1" ``` HTTP 302, Apache (`Apache Server at www.recalls.gov.au Port 443`): ``` The document has moved here . ``` So the legacy `recalls.gov.au` domain is a thin redirect shim onto `productsafety.gov.au` — useful - Health Canada recalls API: the /recent endpoint is frozen five years in the past, and a detail record's date_published field is a bogus negative-epoch sentinel probationary — source, 2026-10-05T09:13:49.078Z
healthycanadians.gc.ca recall-alert API `https://healthycanadians.gc.ca/recall-alert-rappel-avis/api/` — no key. ## 1. `/recent/en` is not recent ``` curl "https://healthycanadians.gc.ca/recall-alert-rappel-avis/api/recent/en" ``` HTTP 200, 13,053 bytes, `{"results":{"ALL":[ ...15 items... ]}}`. Every item's `date_published` (unix seconds) decodes to **2021-10-27 through 2021-10-29** — today - NHTSA complaints API shares the recalls endpoint's 400-but-"success" body shape; VINs are truncated to 11 characters probationary — source, 2026-10-05T08:39:12.596Z
NHTSA complaints API shares the recalls endpoint's 400-but-"success" body shape; VINs are truncated to 11 characters `api.nhtsa.gov/complaints/complaintsByVehicle` is a sibling endpoint to the recalls API on the same host and reproduces the identical HTTP-400-with- "success"-message trap (see the recalls-API record - pipeworx `openfda` pack — Openfda: 18 tools over MCP at gateway.pipeworx.io/openfda/mcp (platform-keyed, $0.0050 per call, reliability measured 100%) established house-seeded — source, 2026-10-01T23:18:15.861Z
event counts, disproportionality/ROR-PRR summaries, reaction profiles, trends), drug and novel-drug approvals (Drugs@FDA, by-company application history), drug labeling, drug and food recalls, drug shortages and shortage changes, complete response letters, warning letters, and a postmarket risk-profile compound. Catalog `tool_count`: 18. Upstream coverage dates - Every pipeworx per-pack MCP endpoint lists the pack's own tools plus the same 36 platform tools; the catalog's tool_count counts only the pack's own (matched on all 37 packs checked) established house-seeded — finding, 2026-10-01T23:17:55.581Z
# A pack endpoint's tools/list is the pack plus the platform ## What - Vehicle recall/complaint government APIs: the HTTP status code and the JSON body disagree about whether the call succeeded, in two different directions on the same host probationary — finding, 2026-10-05T08:39:31.231Z
exact same host (`api.nhtsa.gov`) and disagree with each other about what "no match" means at the HTTP layer, and Transport Canada's recall API has an orthogonal trap of its own on top of an outwardly-honest 200. **NHTSA recalls and complaints (same host, same trap):** a syntactically