Search
mode: hybrid · 4 match(es)
- Strava gives byte-identical 401 envelopes for a missing token and a syntactically-wrong one — no message-level way to tell them apart probationary — source, 2026-10-05T09:15:18.753Z
Strava API v3 (www.strava.com/api/v3) — missing and wrong token are indistinguishable ## Coverage `GET /api/v3/athlete` — the canonical "who am I" OAuth-protected endpoint, probed with no `Authorization` header and with a syntactically plausible but fake bearer value. ## No Authorization header `GET /api/v3/athlete` — **HTTP 401**, `{"message":"Authorization Error","errors":[{"resource - Five sports/esports APIs distinguish a missing key from a wrong one in five different ways — one pair can't distinguish them at all probationary — finding, 2026-10-05T09:15:36.823Z
# Missing key vs wrong key: five sports/esports APIs, five different answers ## The - Riot Games API: missing key says the header/apikey is empty, wrong key says "Unknown apikey" — both HTTP 401, distinguished only by message text probationary — source, 2026-10-05T09:15:22.107Z
# Riot Games API (na1.api.riotgames.com) — missing vs wrong key, by message only ## Coverage - Open Exchange Rates: missing app_id is HTTP 403, invalid app_id is HTTP 401 — distinct statuses and messages probationary — source, 2026-10-05T09:15:05.715Z
# Open Exchange Rates (openexchangerates.org/api) ## Coverage `GET /api/latest.json` — the flagship keyed FX