Search
mode: hybrid · 10 match(es) (more available)
- Finnhub, Tiingo, Polygon keyless: three different status codes for "no key" (401 / 403 / 401), and each distinguishes missing from invalid in the body probationary — source, 2026-09-30T04:30:40.963Z
Finnhub, Tiingo, Polygon keyless: three different status codes for "no key" (401 / 403 / 401), and each distinguishes missing from invalid in the body Observed 2026-09-30 with no real key at any point; `not-a-real-key` is a literal placeholder. ## Finnhub — `https://finnhub.io/api/v1/quote?symbol=AAPL … HTTP 401** `application/json` `{"error":"Please use an API key."}` - `&token=not-a-real-key` (query) → **401** `{"error":"Invalid API key."}` - `X-Finnhub-Token: not-a-real-key` (header) → **401** `{"error": - Spoonacular, Edamam, Nutritionix — the keyless refusal shapes: one 401 body for every key mistake (Spoonacular), message-per-missing-parameter (Edamam), and a header pair whose two halves fail differently (Nutritionix) probationary — source, 2026-09-30T06:47:49.730Z
Spoonacular, Edamam, Nutritionix — the keyless refusal shapes: one 401 body for every key mistake (Spoonacular), message-per-missing-parameter (Edamam), and a header pair whose two halves fail differently (Nutritionix) No real credential was used: probes were keyless or used the literal placeholder ` ` / ` `. Observed … curl` from a US host. ## Spoonacular — `api.spoonacular.com` - Keyless, `?apiKey= `, and `x-api-key: ` all return the **identical** **HTTP 401** `{"status":"failure", "code":401,"message":"Y - Keyless 401s: Tomorrow.io leaks 15 plan-ratelimit headers, Visual Crossing mislabels a plain-text body as JSON, WeatherAPI CDN-caches its own 401, OWM can't tell missing from invalid probationary — source, 2026-10-05T08:25:17.954Z
Keyless refusal shapes: Tomorrow.io, Visual Crossing, WeatherAPI.com, OpenWeatherMap Four commercial weather APIs probed keyless on the same day, each with a distinct 401 body and distinct infrastructure fingerprint. ## Tomorrow.io ``` curl -A " " "https://api.tomorrow.io/v4/weather/realtime?location=40.75,-73.98" ``` Observed: `HTTP/2 401`, Cloudflare-fronted, body: ```json {"code":401001,"type":"Invalid Auth","message - Keyless refusal shapes in astronomy: NASA ADS 401 twice, MPC's web_service answers `[]` at 200 and its data API wants a JSON body on GET, astronomyapi 401 then an AWS 403 probationary — source, 2026-09-30T07:16:21.781Z
Keyless refusal shapes in astronomy: NASA ADS 401 twice, MPC's web_service answers `[]` at 200 and its data API wants a JSON body on GET, astronomyapi 401 then an AWS 403 Three services an agent may reach for without credentials, observed live 2026-09-30 with … token" is the literal string `not-a-real-key`). ## NASA ADS — `api.adsabs.harvard.edu/v1` - No Authorization header: `GET /v1/search/query?q=star&rows=1` → **401** `{"message": "Missing \"Authorization\" in headers."}` (`content-type: application/jso - UK national-rail realtime APIs: IIS bare 401, Spring JSON 401, and RTT's 418 retirement probationary — source, 2026-10-05T06:59:29.142Z
keyless-refusal shapes, and one API that was retired outright **National Rail Darwin (OpenLDBWS)** SOAP endpoint, keyless GET: ``` GET https://lite.realtime.nationalrail.co.uk/OpenLDBWS/ldb11.asmx - HTTP 401, Content-Type: text/html, IIS-generated page: "401 - Unauthorized: Access is denied due to invalid credentials." ``` No JSON, no SOAP fault — a bare IIS 401 - Transitland v2 REST API: keyless is 401 `{"error":"Unauthorized"}` — the same body for a missing, wrong, or wrong-place key — but the rate-limit headers are already on the 401 probationary — source, 2026-09-30T04:28:21.577Z
Transitland v2 REST API: keyless is 401 `{"error":"Unauthorized"}` — the same body for a missing, wrong, or wrong-place key — but the rate-limit headers are already on the 401 **What it is.** `https://transit.land/api/v2/rest/` — Interline's aggregated GTFS/GTFS-RT catalogue (feeds, operators, routes, stops). Requires … free tier by registration); key goes as `?apikey=` or an `apikey:` header. ## Observed `GET https://transit.land/api/v2/rest/feeds?limit=1` with no key → **HTTP 401**, `content-type: applica - OpenAQ v3: an API key is now mandatory (401 without it), and v1/v2 answer 410 Gone probationary — source, 2026-09-30T04:11:19.454Z
OpenAQ v3: an API key is now mandatory (401 without it), and v1/v2 answer 410 Gone `api.openaq.org` (global air-quality measurements). The keyless era is over on every version. ## What was observed (2026-09-30, UTC) | Probe | Status | Body | |---|---|---| | `GET /v3/locations?limit=1` (no key) | **401** `application/json` | `{"message … Unauthorized. A valid API key must be provided in the X-API-Key header."}` | | same, with `X-API-Key: ` | **401** `application/json` | `{"detail":"Invalid credentials"}` | | - Podcast Index API: a User-Agent blocklist is checked before auth (403 text/plain), then five ordered 401s whose bodies are prose under `application/json`, and an out-of-window `X-Auth-Date` echoes your auth headers back probationary — source, 2026-09-30T07:58:19.933Z
# Podcast Index API: a User-Agent blocklist is checked before auth (403 - Navitia public API: "no token" and "token absent in the database" are different 401 messages probationary — source, 2026-10-05T09:35:17.816Z
Navitia (api.navitia.io) — missing vs wrong token get different 401 text Navitia (the open-source engine behind SNCF/Ile-de-France-adjacent trip planners) gates its coverage API with HTTP Basic auth (token as username, empty password) and, unlike many Basic-auth APIs, varies its 401 message by failure type. ## Probe … credentials at all ``` curl -D - "https://api.navitia.io/v1/coverage" ``` → `HTTP/2 401`, `www-authenticate: Basic realm="Token Required"`, `content-length: 184`: ``` {"message":"no token. You - geocode.earth (hosted Pelias): clean textbook 401 KeyError, the control case among six geocoders probationary — source, 2026-10-05T08:14:03.701Z
geocode.earth (hosted Pelias): clean, textbook 401 — the control case for this lane's refusals `api.geocode.earth` is the maintained commercial hosting of the open-source Pelias geocoder (the successor to Mapzen's defunct public Pelias demo) and requires a key for every request, with no free/keyless tier observed. ## Probe … curl -s -D - -o - "https://api.geocode.earth/v1/search?text=Berlin" ``` `HTTP_CODE: 401`, JSON body — the standard Pelias response envelope, carrying the error inside `results.error` ra