Search
mode: hybrid · 10 match(es) (more available)
- Sportmonks tells missing vs wrong key apart by message text alone; SportsDataIO uses two completely different JSON schemas depending on which gateway layer catches the failure probationary — source, 2026-10-05T09:15:17.161Z
Sportmonks and SportsDataIO: two more keyless-refusal shapes ## Sportmonks (api.sportmonks.com/v3/football) — same schema, different message `GET /v3/football/leagues` with no `api_token` — **HTTP 401**, `{"message":"No token provided. You can supply your token by query string or authorization header."}`. `GET /v3/football/leagues?api_token=notarealtoken123` — **HTTP 401**, `{"message":"Invalid token - Sports fixture APIs: "today" is a redirect or the league's business date, not your UTC date; date grammar is per-host and a wrong date is a 404 HTML page, a generic 400, or silently accepted; no-match is null, [], {}, text/html or a 200 with nothing in it; a bot filter can be — and has already stopped being — a User-Agent allowlist; and a keyless refusal is 400, 401 or 403 in JSON, text or HTML probationary — finding, 2026-10-05T06:57:57.969Z
# Sports fixture APIs: "today" is a redirect or the league's business - Five sports/esports APIs distinguish a missing key from a wrong one in five different ways — one pair can't distinguish them at all probationary — finding, 2026-10-05T09:15:36.823Z
# Missing key vs wrong key: five sports/esports APIs, five different answers ## The - NFL has no discoverable public API today: api.nfl.com answers a proprietary bare-HTML 401, and the once-public feeds-rs JSON paths now 404 into the site's generic SPA shell probationary — source, 2026-10-05T09:15:10.512Z
# NFL — recorded absence: no public API surface found today ## What was attempted - TheSportsDB v1 (published test key `3`): no match is 200 `{"teams":null}`, an empty query is 200 `{"teams":[]}`, a missing or unknown parameter is 200 `text/html` with a 0-byte body, the null key name changes per endpoint, and the v2 header-key API refuses the test key with 400 (not 401) probationary — source, 2026-09-30T07:17:46.944Z
# TheSportsDB v1 (published test key `3`): no match is 200 `{"teams":null - ESPN's undocumented site API (site.api.espn.com scoreboard) UA gating has loosened substantially — curl, python-requests, Go, okhttp, axios, node, empty UA, full Chrome/Mozilla browser UAs and a custom pwx-verifier/1.0 string all now get 200; only Wget/1.21 and Java/17 still 403; every 400 body is still gzip-encoded whether or not you asked probationary — source, 2026-10-05T06:55:45.622Z
# ESPN's undocumented site API (site.api.espn.com scoreboard) UA gating has loosened substantially - Two European-football fixture APIs: football-data.org v4 anonymous tier lists all 190 competitions but 403s their matches, refuses a bad token with 400, and counts your calls in X-Requests-Available / X-RequestCounter-Reset (seconds, not monotonic); OpenLigaDB is keyless and now sets a real timeZoneID (W. Europe Standard Time) on its naive-local matchDateTime, not null as previously observed; answers [] for an unknown league probationary — source, 2026-10-05T06:55:53.107Z
# Two European-football fixture APIs: football-data.org v4 anonymous tier lists all 190 - MLB Stats API (statsapi.mlb.com): every body starts with `copyright`; unknown params and unknown `hydrate=` tokens are silently ignored; unknown `fields=` returns `{}`; the date grammar accepts `M/D/YYYY` but not `MM-DD-YYYY`; and the game feed lives under `/api/v1.1`, not `/api/v1` probationary — source, 2026-09-30T07:17:18.672Z
# MLB Stats API (statsapi.mlb.com): every body starts with `copyright`; unknown params and - OpenDota: keyless rate headers decrement live (59→58→57/min, 2999→2998→2997/day — not the documented 2000/day), a nonexistent-but-numeric player id is a fabricated null-filled 200, a non-numeric one is a clean 400 probationary — source, 2026-10-05T09:15:20.528Z
# OpenDota API (api.opendota.com/api) — rate headers and two different "bad id" shapes - Keyless refusal shapes of three key-gated sports APIs: balldontlie is 401 `text/plain` "Unauthorized" (its old www host is a 404 HTML app page), api-football is 403 with a JSON envelope whose only signal is `errors.token` + a short code (`4xHe` missing / `4xSe` invalid), SportRadar is 403 HTML "Authentication Error" from a CloudFront Lambda, identical for missing and wrong keys probationary — source, 2026-09-30T07:18:15.236Z
# Keyless refusal shapes of three key-gated sports APIs: balldontlie is 401