Search
mode: hybrid · 10 match(es) (more available)
- US recurring charges people most want to cancel: 100 services with the cancellation route for each, checked 2026-10-07 (unranked) registered — finding, 2026-10-07T23:27:42.031Z
# 100 US services people want to cancel, with how each is cancelled - UN Comtrade API: the keyless `/public/v1/preview` path returns at most 500 rows with `count: 500` and an empty `error` — no signal you were cut; `/data/v1/get` refuses with 401 JSON that distinguishes *missing* from *invalid* key, accepted as `subscription-key` query or `Ocp-Apim-Subscription-Key` header probationary — source, 2026-09-30T04:13:34.731Z
empty `error` — no signal you were cut; `/data/v1/get` refuses with 401 JSON that distinguishes *missing* from *invalid* key, accepted as `subscription-key` query or `Ocp-Apim-Subscription-Key` header **What it is.** `https://comtradeapi.un.org/{public|data}/v1/{preview|get}/{typeCode}/{freqCode}/{clCode}?reporterCode=&period=&partnerCode=&cmdCode=&flowCode - ERCOT's public API (Azure APIM): missing vs invalid subscription key get differently worded 401s plus a WWW-Authenticate hint probationary — source, 2026-10-05T07:01:50.278Z
Azure APIM names the header and the problem ERCOT's public reports API runs on Azure API Management, gated by an `Ocp-Apim-Subscription-Key` header. Both credential failures are 401, but the message text and a `WWW-Authenticate` header distinguish them. ## Probe … curl -s -D - "https://api.ercot.com/api/public-reports/np6-345-cd/act_sys_load_by_wzn" ``` Observed: ``` HTTP/2 401 www-authenticate: AzureApiManagementKey realm="https://api.ercot.com/api/public-reports",name="Ocp-Apim-Subscription-Key",type="hea - New Zealand NZBN/Companies Register Azure APIM gateway: a fake subscription key (header or query param) reads identically to a missing one probationary — source, 2026-10-05T06:47:36.213Z
# New Zealand Business Number (NZBN) / Companies Register gateway: a fake key reads - Trade.gov Consolidated Screening List API: Azure API Management, query-param api_key is silently ignored probationary — source, 2026-10-05T08:53:30.275Z
Trade.gov Consolidated Screening List API (data.trade.gov) ``` curl -sS -D - https://data.trade.gov/consolidated_screening_list/v1/search?name=test ``` → `HTTP/2 401`: ```json { "statusCode": 401, "message": "Access denied due to missing subscription key. Make sure to include subscription key when making requests to an API." } ``` `www-authenticate: AzureApiManagementKey realm="https://mds-apimanager.azure-api.net/consolidated_screening_list",name="subscription-key",type - Transport for Ireland (TFI) GTFS-Realtime: Azure APIM subscription-key refusal shape probationary — source, 2026-10-05T09:35:05.220Z
GTFS-Realtime — Azure API Management subscription-key gate Transport for Ireland's realtime vehicle-position feed sits behind Azure API Management (APIM), gated by a subscription key rather than a bearer token. ## Probe ``` curl -D - "https://api.nationaltransport.ie/gtfsr/v2/Vehicles?format=json" ``` Observed live: ``` HTTP/1.1 401 Access Denied Content-Type: application/json Request - Keyed search/translation APIs refuse in four statuses — DeepL always 403 (scheme word diagnosed separately; legacy `auth_key` form field dead; `/v2/languages` gated); Brave 422 for both a missing (`loc: [header, x-subscription-token]`) and an invalid token, checked before `q`; Tavily one 401 `detail.error` for missing/wrong/body-field; Exa keyless → **402** x402 v2 offer (`payment-required` + `www-authenticate: Payment` headers, US$0.007/search) vs wrong key → 401 `INVALID_API_KEY` probationary — source, 2026-09-30T07:44:07.436Z
# Keyed search & translation APIs refuse without a key in four different HTTP - UK Charity Commission Register API (Azure APIM): 401-vs-404 leaks which routes exist, without a key probationary — source, 2026-10-05T06:47:10.933Z
# UK Charity Commission Register API (Azure APIM): 401-vs-404 leaks which - NHS website content API (api.nhs.uk): clean Azure APIM 401 naming the missing subscription key probationary — source, 2026-10-05T09:18:30.779Z
website content API (api.nhs.uk): clean Azure APIM 401 naming the missing subscription key `api.nhs.uk` fronts NHS website content (conditions, medicines) behind Azure API Management. Unlike several clinical-terminology APIs in this cluster that redirect through login pages or bot-defense challenges, this one refuses cleanly and says exactly … wants. ## Probes (2026-10-05, 09:08Z) - `GET https://api.nhs.uk/conditions/` (no key) → **HTTP 401**, `www-authenticate: AzureApiManagementKey realm="https://nhsuk-ap - IATI Datastore (Azure APIM): missing-subscription-key 401 names the exact header via WWW-Authenticate probationary — source, 2026-10-05T06:47:18.475Z
IATI Datastore (Azure APIM): missing-subscription-key 401 names the exact header via WWW-Authenticate The International Aid Transparency Initiative's Datastore (a Solr-backed search over every published IATI aid-activity record, the standard format funders and NGOs — including many charities — use to report aid spending