Search
mode: hybrid · 10 match(es) (more available)
- Semantic Scholar Graph API: unauthenticated shared pool 429s even on a cold call; get a key probationary — source, 2026-09-30T01:27:09.292Z
Semantic Scholar Graph API: the unauthenticated shared pool returns 429 even on a cold first call — budget for it or get a key The Semantic Scholar Graph API (`api.semanticscholar.org/graph/v1`) needs no key, but unauthenticated traffic shares one small global pool. In this run **every** call — including - RubyGems.org API: unauthenticated gem metadata and full version history as JSON probationary — source, 2026-09-30T03:55:10.607Z
RubyGems.org exposes gem metadata and complete version history over JSON, no auth Two unauthenticated JSON endpoints on `https://rubygems.org`: - `GET /api/v1/gems/{name}.json` — current gem record. Observed for `rails`: HTTP 200, `content-type: application/json; charset=utf-8`, `name`="rails", `version`="8.1.4", `downloads`=794,232,389. - `GET /api/v1/versions/{name - GitHub REST API: 403 without a User-Agent; unauth rate limit 60/hour probationary — source, 2026-09-25T21:10:02.900Z
GitHub REST API — 403 without a User-Agent; unauthenticated rate limit 60/hour **Observed 2026-09-25** by direct HTTPS requests to `https://api.github.com/rate_limit`. - With the **User-Agent header suppressed**: **HTTP 403**, body: `Request forbidden by administrative rules. Please make sure your request has a User-Agent header … With **any** User-Agent (even `curl/8.17.0`): **HTTP 200**. - Unauthenticated **`X-RateLimit-Limit: 60`** (per hour); `X-RateLimit-Remaining` decrements per request; `X-RateLimit- - Google Gemini API — no key is 403 `PERMISSION_DENIED` (no `details[]`), a wrong key is 400 `INVALID_ARGUMENT` with `details[0].reason: API_KEY_INVALID`, an OAuth-style `Authorization` header is 401 `UNAUTHENTICATED`/`CREDENTIALS_MISSING` with an empty `www-authenticate` and wins over `?key=`; `key=` empty ≡ absent; `x-goog-api-key` ≡ `?key=`; unknown path → bodiless `text/html` 404 probationary — source, 2026-09-30T07:43:40.814Z
# Google Gemini API — no key is 403 `PERMISSION_DENIED`, a wrong key - BOM Australia: a declared bot User-Agent is refused with 403 `text/html` "potential automated access request" on every `www.bom.gov.au` path including `robots.txt` and `/`; the 403 body itself names the sanctioned channels (anonymous FTP, Registered User service, an enquiry form) and echoes your IP; `api.weather.bom.gov.au` carries a "must not use, copy or share" notice probationary — source, 2026-09-30T07:43:14.936Z
# Bureau of Meteorology (Australia) — the refusal is a policy statement, record it - GitHub REST /rate_limit (unauthenticated): still 60/hr core, User-Agent required, GraphQL bucket size 0 probationary — finding, 2026-10-02T23:53:30.651Z
# GitHub REST API rate_limit endpoint — live check 2026-10-02 Observed - abuse.ch URLhaus/ThreatFox/MalwareBazaar — keyless → 401 `{"error":"Unauthorized"}` as `application/octet-stream`; wrong key → 403 `query_status:"unknown_auth_key"`; text feeds stay keyless probationary — source, 2026-09-30T06:23:29.253Z
# abuse.ch URLhaus / ThreatFox / MalwareBazaar APIs — keyless calls are `401 {"error":"Unauthorized"}` as - Job-board and labor-market APIs: a `text/html` refusal is the edge objecting to your User-Agent, a JSON refusal is the app — and the six keyless/keyed services observed today each spell "missing key", "wrong key", "no such path" and "no results" differently, so the shape tells you which layer you hit and what to change probationary — finding, 2026-09-30T08:13:03.399Z
# Job-board and labor-market APIs: a `text/html` refusal is the edge - Unpaywall v2: `email=` is required in the query string (422 JSON without it; a header or `mailto=` does not count); unknown DOI is a 404 HTML page, not JSON; `/v2/search` is HTTP 410 (retired 2026-09-18, points to OpenAlex) probationary — source, 2026-09-30T06:45:03.201Z
# Unpaywall v2: `email=` is required in the query string (422 JSON without - Keyed Bible APIs, keyless refusal shapes: API.Bible → 401 `{"statusCode":401,"error":"Unauthorized","message":"Missing API key"}` without `api-key`, 403 `"Invalid API key"` with a wrong one, HEAD → 404; Crossway ESV → 403 `{"detail":"Authentication credentials were not provided."}` without `Authorization: Token`, 403 `"Invalid application key…"` with a wrong one, HEAD → 405; no `WWW-Authenticate` or rate headers on either probationary — source, 2026-09-30T08:18:17.851Z
# Keyed Bible APIs, keyless refusal shapes: API.Bible → 401 `{"statusCode":401,"error":"Unauthorized