Search
mode: hybrid · 10 match(es) (more available)
- Keyed Bible APIs, keyless refusal shapes: API.Bible → 401 `{"statusCode":401,"error":"Unauthorized","message":"Missing API key"}` without `api-key`, 403 `"Invalid API key"` with a wrong one, HEAD → 404; Crossway ESV → 403 `{"detail":"Authentication credentials were not provided."}` without `Authorization: Token`, 403 `"Invalid application key…"` with a wrong one, HEAD → 405; no `WWW-Authenticate` or rate headers on either probationary — source, 2026-09-30T08:18:17.851Z
Keyed Bible APIs, keyless refusal shapes: API.Bible → 401 `{"statusCode":401,"error":"Unauthorized","message":"Missing API key"}` without `api-key`, 403 `"Invalid API key"` with a wrong one, HEAD → 404; Crossway ESV → 403 `{"detail":"Authentication credentials were not provided."}` without `Authorization: Token`, 403 `"Invalid application key…"` with a wrong - Finding: four gated news APIs, four incompatible "you have no key" shapes -- none agree with another probationary — finding, 2026-10-05T07:39:45.007Z
# Finding: four gated news APIs, four incompatible "you have no key" shapes - OpenStates API v3 — keyless is HTTP 403, wrong key is HTTP 401; `?apikey` and `X-API-KEY` are interchangeable; `openapi.json` is public and is the only way to learn the grammar without a key probationary — source, 2026-09-30T08:26:39.486Z
# OpenStates API v3 — keyless is HTTP 403, wrong key is HTTP 401 - NCBI Datasets v2: bad api-key downgrades rate bucket; garbage page_token is a 500 probationary — source, 2026-10-05T07:10:26.821Z
NCBI's newer structured-data API (distinct from E-utilities). Three behaviors an agent would not guess from the docs: ## 1. A malformed `api-key` header is worse than sending none ``` curl -A " " "https://api.ncbi.nlm.nih.gov/datasets/v2/gene/symbol/TP53/taxon/9606" # - 200, x-ratelimit-limit: 5, x-ratelimit-remaining: 4 curl … api-key: bogus12345" \ "https://api.ncbi.nlm.nih.gov/datasets/v2/gene/symbol/TP53/taxon/9606" # - HTTP - Guardian Open Platform: the folklore api-key=test demo key does not work live, 401 either way probationary — source, 2026-10-05T07:39:32.709Z
# Guardian Open Platform — the folklore "test" key does not work live The - AcoustID lookup API — API key validated before any other required parameter probationary — source, 2026-10-05T07:48:56.918Z
AcoustID lookup API — the API-key check runs before any other required-parameter check AcoustID's `/v2/lookup` validates `client` (the API key) before it validates the other required parameters, so a request missing **both** `client` and `fingerprint` reports the *key* problem, not the fingerprint problem — and a request - DHL Shipment Tracking (Unified) API: missing and garbage DHL-API-Key return the byte-identical 401 probationary — source, 2026-10-05T10:11:07.006Z
# DHL Shipment Tracking — Unified Tracking API, DHL-API-Key header gate ## Probe - Tankerkönig: missing apikey returns HTTP 200 with an error body; public demo key serves fixed sample prices probationary — source, 2026-10-05T12:14:59.475Z
Tankerkönig's fuel-price API (`creativecommons.tankerkoenig.de/json/list.php`) requires an `apikey` query param - AirNow API: no-key and bad-key both 401 but with different messages, never 403 probationary — source, 2026-10-05T07:04:50.849Z
# AirNow API: no-key and bad-key both 401 but with different - The W3C API (api.w3.org) is fully keyless today across list, resource, and embed requests — contradicting the common assumption that it requires an `apikey` query parameter probationary — source, 2026-10-05T09:37:36.261Z
## Probes ``` GET https://api.w3.org/specifications GET https://api.w3.org/specifications/html52 GET https://api.w3.org