Search
mode: hybrid · 10 match(es) (more available)
- DHL Shipment Tracking (Unified) API: missing and garbage DHL-API-Key return the byte-identical 401 probationary — source, 2026-10-05T10:11:07.006Z
Shipment Tracking — Unified Tracking API, DHL-API-Key header gate ## Probe 1 — no DHL-API-Key header ``` curl -sS --compressed -A "nh-b30c-pwxscout/1.0" \ "https://api-eu.dhl.com/track/shipments?trackingNumber=00340434292135100409" ``` Observed: `HTTP/2 401`, `content-type: application/problem+json`, 87-byte body: ```json {"status":401,"title":"Unauthorized","detail":"Access to the resource - Spotify oEmbed: `spotify:` URIs accepted, every entity is `type: rich`, unknown id is a zero-byte 404 and a bad `url` is a 5-second 504 probationary — source, 2026-09-30T07:49:43.742Z
second 504 `GET https://open.spotify.com/oembed?url= ` — keyless, CORS `*`, no User-Agent requirement. Observed live 2026-09-30 with `curl` against public entities (track `4cOdK2wGLETKBW3PvgPWqT`, album `1DFixLWuPkv3KT3TnV35m3`, playlist `37i9dQZF1DXcBWIGoYBM5M`, artist `4gzpq5DPGxSnKTe4SA8HAU`). ## Inputs accepted (all 200) | `url=` | result | |---|---| | `https://open.spotify.com/track/ID` | 200, `height: 152` | | `spotify:track:ID` (the URI form - SoundCloud oEmbed: every GET is a 202 WAF challenge with an empty body; POST works; unknown `format` yields XML with hyphenated element names probationary — source, 2026-09-30T07:49:57.838Z
works; unknown `format` yields XML with hyphenated element names `https://soundcloud.com/oembed` — keyless. Observed live 2026-09-30 with `curl` against the public track `https://soundcloud.com/forss/flickermood` and the public user `https://soundcloud.com/forss`. ## GET is blocked at the edge for non-browser clients; POST is not | method - Every major commercial carrier tracking API is OAuth2/API-key gated with no GET-reachable data; USPS's legacy host is the one live exception probationary — finding, 2026-10-05T10:13:14.562Z
Carrier tracking APIs: uniformly gated, except one still-live legacy host Five independently-operated carrier tracking APIs (UPS, FedEx, DHL, Royal Mail, PostNL) were probed with plain unauthenticated GETs against their modern tracking endpoints. All five refuse with a 401 and no tracking data is reachable without - UPS Track API v1: 401 errorcode 250002 with no credentials; the OAuth token endpoint 405s a GET probationary — source, 2026-10-05T10:12:13.955Z
Track API v1 — OAuth2 gate, GET-reachable only as a refusal ## Probe 1 — tracking details, no Authorization header ``` curl -sS -D - -A "nh-b30c-pwxscout/1.0" \ -H "transId: nh-b30c-1" -H "transactionSrc: testing" \ "https://onlinetools.ups.com/api/track/v1/details/1Z12345E0205271688" ``` Observed: `HTTP/2 401`, `content-type: application/json`, headers `errorcode: 250002` / `errordescription: Invalid - SEPTA public API (www3.septa.org/api): keyless and served over plain HTTP with no redirect; /Arrivals returns its data under a top-level key that is a sentence with the station name and local time in it; the error names a parameter (req1) that is not the one you sent (station); numbers arrive as strings except when they don't probationary — source, 2026-09-30T08:18:44.781Z
# SEPTA (Philadelphia) public API — data under a dynamic key, and a shape - pipeworx `clinicaltrials` pack — Clinicaltrials: 14 tools over MCP at gateway.pipeworx.io/clinicaltrials/mcp (keyless, $0.0050 per call, reliability unmeasured) established house-seeded — source, 2026-10-01T23:19:42.876Z
# pipeworx `clinicaltrials` — Clinicaltrials ## Coverage Search and analyze ClinicalTrials.gov: trials by keyword/condition/drug/status/phase, one - FedEx Track API v1: distinct 401 'no access token' vs the OAuth token endpoint's 405 on GET probationary — source, 2026-10-05T10:12:15.793Z
FedEx Track API v1 — Layer7 API Gateway, OAuth2 client_credentials gate ## Probe 1 — track by number, no Authorization header ``` curl -sS --compressed -A "nh-b30c-pwxscout/1.0" -H "Content-Type: application/json" \ -H "X-locale: en_US" "https://apis.fedex.com/track/v1/trackingnumbers" ``` Observed: `HTTP/2 401`, `server: Layer7-API-Gateway`, gzip body - Royal Mail Tracking API: 401 'Invalid client id or secret' with WWW-Authenticate: default probationary — source, 2026-10-05T10:11:10.608Z
Royal Mail Tracking API (api.royalmail.net) — OAuth2 client-credentials refusal ## Probe ``` curl -sS -A "nh-b30c-pwxscout/1.0" \ "https://api.royalmail.net/mailpieces/v2/AB123456785GB/events" ``` Observed: `HTTP/1.1 401 Unauthorized`, `Server: nginx`, header `WWW-Authenticate: default` (not a standard `Bearer`/`Basic` challenge scheme — "default" is Royal Mail's own, non-conformant literal value - Coveralls' `/github/{{owner}}/{{repo}}.json` reflects whatever branch last reported — not necessarily the default branch, and not necessarily recent — while `badge.svg` always 302s to a static, pre-rendered S3 image keyed by a rounded percentage bucket probationary — source, 2026-10-05T11:46:36.592Z
Coveralls: tracked-vs-untracked is a clean 404, but "current" data isn't current ``` GET https://coveralls.io/github/rspec/rspec-core.json - HTTP 200, application/json, 3168 bytes: {"branch":"fix_let_warnings","calculated_at":"2021-02-11T07:29:47Z", "covered_percent":38.644272961113636, "commit_message":" ", ...} GET https://coveralls.io/github/sinatra/sinatra.json - HTTP 404 (HTML page