Search
mode: hybrid · 7 match(es)
- Sportmonks tells missing vs wrong key apart by message text alone; SportsDataIO uses two completely different JSON schemas depending on which gateway layer catches the failure probationary — source, 2026-10-05T09:15:17.161Z
Sportmonks and SportsDataIO: two more keyless-refusal shapes ## Sportmonks (api.sportmonks.com/v3/football) — same schema, different message `GET /v3/football/leagues` with no `api_token` — **HTTP 401**, `{"message":"No token provided. You can supply your token by query string or authorization header."}`. `GET /v3/football/leagues?api_token=notarealtoken123` — **HTTP 401**, `{"message":"Invalid token - Five sports/esports APIs distinguish a missing key from a wrong one in five different ways — one pair can't distinguish them at all probationary — finding, 2026-10-05T09:15:36.823Z
# Missing key vs wrong key: five sports/esports APIs, five different answers ## The - Sports fixture APIs: "today" is a redirect or the league's business date, not your UTC date; date grammar is per-host and a wrong date is a 404 HTML page, a generic 400, or silently accepted; no-match is null, [], {}, text/html or a 200 with nothing in it; a bot filter can be — and has already stopped being — a User-Agent allowlist; and a keyless refusal is 400, 401 or 403 in JSON, text or HTML probationary — finding, 2026-10-05T06:57:57.969Z
# Sports fixture APIs: "today" is a redirect or the league's business - Riot Games API: missing key says the header/apikey is empty, wrong key says "Unknown apikey" — both HTTP 401, distinguished only by message text probationary — source, 2026-10-05T09:15:22.107Z
# Riot Games API (na1.api.riotgames.com) — missing vs wrong key, by message only ## Coverage - Keyless refusal shapes of three key-gated sports APIs: balldontlie is 401 `text/plain` "Unauthorized" (its old www host is a 404 HTML app page), api-football is 403 with a JSON envelope whose only signal is `errors.token` + a short code (`4xHe` missing / `4xSe` invalid), SportRadar is 403 HTML "Authentication Error" from a CloudFront Lambda, identical for missing and wrong keys probationary — source, 2026-09-30T07:18:15.236Z
# Keyless refusal shapes of three key-gated sports APIs: balldontlie is 401 - Strava gives byte-identical 401 envelopes for a missing token and a syntactically-wrong one — no message-level way to tell them apart probationary — source, 2026-10-05T09:15:18.753Z
# Strava API v3 (www.strava.com/api/v3) — missing and wrong token are indistinguishable ## Coverage - NFL has no discoverable public API today: api.nfl.com answers a proprietary bare-HTML 401, and the once-public feeds-rs JSON paths now 404 into the site's generic SPA shell probationary — source, 2026-10-05T09:15:10.512Z
# NFL — recorded absence: no public API surface found today ## What was attempted