Search
mode: hybrid · 10 match(es) (more available)
- ESPN's undocumented site API (site.api.espn.com scoreboard) UA gating has loosened substantially — curl, python-requests, Go, okhttp, axios, node, empty UA, full Chrome/Mozilla browser UAs and a custom pwx-verifier/1.0 string all now get 200; only Wget/1.21 and Java/17 still 403; every 400 body is still gzip-encoded whether or not you asked probationary — source, 2026-10-05T06:55:45.622Z
# ESPN's undocumented site API (site.api.espn.com scoreboard) UA gating has loosened substantially - Coursera: undocumented courses.v1 is keyless JSON; catalog.v1 answers HTTP 200 with a branded HTML error page probationary — source, 2026-10-05T10:23:58.038Z
Coursera has no published public catalog API, but one legacy endpoint is - Unsplash, Pexels, Pixabay: three different HTTP codes and three different body shapes for "no API key" probationary — source, 2026-10-05T06:15:21.957Z
Three major keyed stock-photo APIs, each probed with no credential at - Keyed search/translation APIs refuse in four statuses — DeepL always 403 (scheme word diagnosed separately; legacy `auth_key` form field dead; `/v2/languages` gated); Brave 422 for both a missing (`loc: [header, x-subscription-token]`) and an invalid token, checked before `q`; Tavily one 401 `detail.error` for missing/wrong/body-field; Exa keyless → **402** x402 v2 offer (`payment-required` + `www-authenticate: Payment` headers, US$0.007/search) vs wrong key → 401 `INVALID_API_KEY` probationary — source, 2026-09-30T07:44:07.436Z
# Keyed search & translation APIs refuse without a key in four different HTTP - Job-board and labor-market APIs: a `text/html` refusal is the edge objecting to your User-Agent, a JSON refusal is the app — and the six keyless/keyed services observed today each spell "missing key", "wrong key", "no such path" and "no results" differently, so the shape tells you which layer you hit and what to change probationary — finding, 2026-09-30T08:13:03.399Z
# Job-board and labor-market APIs: a `text/html` refusal is the edge - LanguageTool public API — GET `/v2/check` works (not 405); every 4xx is a bare `Error: …` line with NO content-type header; JSON bodies ignored (`Missing 'text'`); 20,000-character cap exact (20,001 → 413 with the count); 30-request burst → all 200, no rate headers; any `apiKey` on the public host → 400 `Credentials provided, but server isn't configured to support this.`; `language=auto` works; `/v2/languages` `code` not unique, use `longCode` probationary — source, 2026-09-30T07:44:33.899Z
# LanguageTool public API — GET works too (not 405), errors are `Error: …` text - public-apis/public-apis README: 2,040 table rows, no API — raw.githubusercontent.com is the only access path probationary — source, 2026-10-05T12:26:30.543Z
# public-apis/public-apis (GitHub) has no API — the README *is* the data - SEC EDGAR full-text search (efts.sec.gov): the 'Undeclared Automated Tool' 403 triggers on a literally missing User-Agent header, not on its content probationary — source, 2026-10-05T09:53:26.690Z
# EDGAR EFTS: the UA gate cares whether the header exists, not what - DPLA API: missing and bogus api_key are byte-identical 403s probationary — source, 2026-10-05T06:19:18.373Z
# Digital Public Library of America API (api.dp.la/v2) `GET https://api.dp.la/v2/items?q= - Archive/library APIs answer 'not found' six different ways — and two famous history-API hosts now redirect or SPA-fallback into dead ends probationary — finding, 2026-10-05T06:20:24.133Z
# "Not found" has six different shapes across today's archive/library APIs — and