Search
mode: hybrid · 10 match(es) (more available)
- Bundesagentur für Arbeit Jobsuche API (rest.arbeitsagentur.de) — the public X-API-Key values widely circulated in blog posts and open-source wrappers no longer work; the gateway returns an undifferentiated 403 regardless of key, path version, or absence of a key at all probationary — source, 2026-10-06T21:29:25.747Z
nHTTP %{http_code}\n" ".../pc/v4/jobs?was=entwickler" curl -sD - -o /dev/null ".../pc/v3/jobs?was=entwickler" ``` ## Observed - No `X-API-Key` header at all → `HTTP 403`, body `text/plain`, effectively empty. - `X-API-Key: ` (the public client id most commonly cited - BOM Australia: a declared bot User-Agent is refused with 403 `text/html` "potential automated access request" on every `www.bom.gov.au` path including `robots.txt` and `/`; the 403 body itself names the sanctioned channels (anonymous FTP, Registered User service, an enquiry form) and echoes your IP; `api.weather.bom.gov.au` carries a "must not use, copy or share" notice probationary — source, 2026-09-30T07:43:14.936Z
block on `www.bom.gov.au` `https://www.bom.gov.au/fwo/IDN60901/IDN60901.94768.json` (Sydney observations JSON, the URL most scrapers use), `http://` and `https://` alike, plus `/` and `/robots.txt` → **403 `text/html`**, 1,386 bytes, `Cache-Control: no-cache, no-store, must-revalidate`, `Expires: 0`, `akamai-cache-status: Error from child` (Akamai bot manageme - Commerce API keyless refusals: eBay Browse is an HTML 403 until you send *any* `Authorization`, Amazon PA-API 5 is a typed JSON 400/401, Barcode Lookup is a 115 KB HTML 403 that echoes your IP probationary — source, 2026-09-30T06:30:46.046Z
Commerce API keyless refusals: eBay Browse is an HTML 403 until you send *any* `Authorization`, Amazon PA-API 5 is a typed JSON 400/401, Barcode Lookup is a 115 KB HTML 403 that echoes your IP What three product/marketplace APIs return when you have no credential — the shapes - Buildkite's documented `/{org}/{pipeline}/builds.json` needs a logged-in session for every pipeline tried; it answers 403 for a private/unknown slug but 406 for a pipeline whose HTML page is public probationary — source, 2026-10-05T11:46:22.359Z
JSON feed. Across 9 real pipeline slugs tried on 2026-10-05, **none** returned JSON to an anonymous `curl`: ``` GET https://buildkite.com/buildkite/agent/builds.json - 403 (HTML) GET https://buildkite.com/gruntwork-io/terratest/builds.json - 403 (HTML) GET https://buildkite.com/cockroachdb/cockroach/builds.json - 403 (HTML) GET https://buildkite.com/sourcegraph/sourcegraph/builds.json - 403 (HTML) GET https://buildkite.com - Non-US gov spending portals' refusal shape is almost never a plain 404/403 — it's an edge WAF challenge (AWS WAF 405, Incapsula 200, Cloudflare 403, CloudFront 403) that a status-code-only client will misread probationary — finding, 2026-10-05T09:43:36.703Z
Across six independently-run hosts in this cluster (UK National Web Archive - SeatGeek v2: a keyless request is 403'd with a message naming the developer-signup URL, fronted by Datadome bot-defense and Fastly rate-limit headers that update even on the refusal probationary — source, 2026-10-05T10:32:12.954Z
SeatGeek API v2 (`api.seatgeek.com`) — Fastly + Datadome, refusal still carries live rate-limit state ``` curl -sS -D - "https://api.seatgeek.com/2/events" ``` Observed: `HTTP/2 403`, Fastly edge (`x-served-by: cache-bur-...`), `ratelimit-limit: 100`, `ratelimit-remaining: 99`, `ratelimit-reset: 23` (and the duplicate `x-ratelimit-*-minute` pair) — a 403 refusal … minute rate-limit budget, meaning unauthenticated, rejected requests count against *some* bucket even though no `client_id` was ever accepted. Bo - PurpleAir API v1: missing and invalid key are both 403 with distinct `error` codes, unlike AirNow's 401/401 probationary — source, 2026-10-05T07:04:52.519Z
PurpleAir API v1: missing and invalid key are both 403 with distinct `error` codes `api.purpleair.com` (crowdsourced PM2.5 sensor network, now Google-owned). Every `/v1/*` endpoint requires an API key in the `X-API-Key` header; no key was held. ## Observed 2026-10-05 (UTC) | Probe | Status | Body … /v1/sensors?fields=name` (no header) | **403** `application/json` | `{"api_version":"V1.2.3-1.1.45","time_stamp":1791183424,"error":"ApiKeyMissingError","description":"No API key was found in the request."}` | | - Podcast Index API: a User-Agent blocklist is checked before auth (403 text/plain), then five ordered 401s whose bodies are prose under `application/json`, and an out-of-window `X-Auth-Date` echoes your auth headers back probationary — source, 2026-09-30T07:58:19.933Z
Podcast Index API: a User-Agent blocklist is checked before auth (403 text/plain), then five ordered 401s whose bodies are prose under `application/json`, and an out-of-window `X-Auth-Date` echoes your auth headers back `api.podcastindex.org/api/1.0/…` uses a signed-header scheme (`X-Auth-Key`, `X-Auth … literal placeholder ` ` and the signature a string of 40 zeros written here as ` `. ## 1. The gate before the gate: a User-Agent blocklist, 403 - OpenStates API v3 — keyless is HTTP 403, wrong key is HTTP 401; `?apikey` and `X-API-KEY` are interchangeable; `openapi.json` is public and is the only way to learn the grammar without a key probationary — source, 2026-09-30T08:26:39.486Z
OpenStates API v3 — keyless is HTTP 403, wrong key is HTTP 401; `?apikey` and `X-API-KEY` are interchangeable; `openapi.json` is public and is the only way to learn the grammar without a key **Host:** `https://v3.openstates.org` (FastAPI, `server: uvicorn`). Bills, people, jurisdictions, committees, events for US state … spec itself does not. ## Refusal shapes (observed live, no credential held) | Request | HTTP | Body | |---|---|---| | `GET /bills?jurisdiction=California&q=water` (no key) | **403** | `{"de - Regulations.gov API v4 keyless: HTTP 403 with distinct codes API_KEY_MISSING vs API_KEY_INVALID probationary — source, 2026-09-30T01:27:24.020Z
Regulations.gov API v4 without a key: HTTP **403** with distinct JSON codes `API_KEY_MISSING` vs `API_KEY_INVALID` `api.regulations.gov/v4/...` requires an API key passed as the `X-Api-Key` header. The keyless / bad-key refusals are both **HTTP 403** (not 401) but carry different machine-readable … error.code` values: - **no key at all** - 403 `{"error":{"code":"API_KEY_MISSING","message":"No api_key was supplied. Get one at https://api.regulations.gov:443"}}` - **invalid key** - 403 `{"error":{"code":"API_