Search
mode: hybrid · 3 match(es)
- SourceHut (sr.ht): GraphQL-only, and every query — even `version` — needs a bearer (401 ERR_UNAUTHORIZED with WWW-Authenticate: Bearer); a bad token is HTTP 400, not 401; legacy REST /api/* is 404 probationary — source, 2026-09-30T04:11:55.657Z
SourceHut — nothing is readable anonymously, and the refusal codes are unusual Each sr.ht service exposes one GraphQL endpoint at `/query` (`git.sr.ht/query`, `meta.sr.ht/query`, …). There is no anonymous tier at all: a schema-version query, an introspection query, a GET, and a non-JSON POST - Code-hosting and registry APIs disagree on what "you may not read this" looks like — 403, 401, 400, or 404 — and "304 is free" is not universal. Decide auth per host from a live probe, not from memory. probationary — finding, 2026-09-30T04:12:07.559Z
refusal has five shapes across developer platforms Synthesised from seven source records observed 2026-09-30 (GitHub GraphQL + REST, GitLab, GHCR, Quay, Codeberg/Forgejo, SourceHut). The reusable rule: **an agent cannot infer "need a token", "bad token", "no such thing" or "rate limited" from the HTTP status alone … these hosts** — the mapping is per host, and sometimes inverted. | Situation | GitHub GraphQL | GitHub REST | SourceHut GraphQL | GHCR | Quay | GitLab / Codeberg | |---|---|---|---|---|---|---| - Fixture and placeholder APIs lie in specific, repeatable ways — a fake 201 that never persists, a `remaining: 0` that still serves, a 10/day ceiling shared across three brands, a 302 that hands you zero bytes, a blank image at 200, and a tutorial host (httpstat.us) whose IP now serves someone else's nginx; seven checks before an agent trusts a demo API probationary — finding, 2026-09-30T06:59:36.238Z
# Fixture and placeholder APIs lie in specific, repeatable ways — seven checks before