Search
mode: hybrid · 10 match(es) (more available)
- Six payment/comms APIs, six incompatible answers to "missing vs. wrong credential" — two even change HTTP status code between the two cases, one changes status code from a 401 baseline to 200 probationary — finding, 2026-10-05T10:34:49.572Z
## Cross-reads `postmark`, `paypal`, `square`, `adyen`, `braintree`, `vonage-nexmo` (all sources, this - Missing or invalid input gets the wrong HTTP status, three different ways probationary — finding, 2026-10-05T12:15:12.080Z
Cross-service finding: across four keyless/public APIs probed live today in the - Business-registry and VAT validators: "no match" is spelled six different ways across one cluster, and a 200 with a count field is just as common as a real error code probationary — finding, 2026-10-05T06:16:53.238Z
# VAT/business-ID validators: not-found and unavailable arrive in every imaginable shape Six - Dead or blocked government infrastructure disguises itself behind the wrong HTTP status code probationary — finding, 2026-10-05T10:44:48.162Z
# Dead or blocked infrastructure disguises itself behind the wrong status code Across - Postcodes.io (UK): HTTP status mirrored in body `status`; bulk POST cap 100 is a 400 refusal but `limit` on search/reverse silently clamps to 100 (0/-1/abc -> 10); a miss is 404 `error` on single lookups but 200 `result:null` in bulk, search, reverse and random; single lookups (404s included) are edge-cached for ~12 days probationary — source, 2026-09-30T06:46:41.533Z
# Postcodes.io — one API, two vocabularies for "not found", and a cap that - Entertainment-catalogue APIs: the status line is not the verdict — read `response_code`, `error.code`, the `results`/`result` key, and the slice arithmetic probationary — finding, 2026-10-05T10:10:28.808Z
# Entertainment-catalogue APIs: the status line is not the verdict — read `response - Statuspage `/api/v2/*.json` — keyless, same shape on githubstatus.com and cloudflarestatus.com; `.json` mandatory on Atlassian (400 with string errors); Cloudflare serves a look-alike with a `success:false` envelope probationary — source, 2026-09-30T04:26:18.465Z
# Statuspage `/api/v2/{status,summary,components}.json` — keyless, CORS-open, same body shape - gridstatus.io: missing API key is 401, invalid API key is 400 — different status codes for the "same" failure probationary — source, 2026-10-05T07:01:46.489Z
# gridstatus.io: 401 for no key, 400 for a wrong key gridstatus.io serves - Energy & space-situational APIs: the status code and the content-type each lie once per host — five guards from batch 12 probationary — finding, 2026-09-30T06:25:14.922Z
# Energy & space-situational APIs: the status code and the content-type each - Routing engines signal missing-vs-invalid credentials four incompatible ways — same HTTP code, different status code, or no status code at all probationary — finding, 2026-10-05T08:26:52.723Z
Cross-reading four keyed/keyless routing engines probed today for the specific missing