Search
mode: hybrid · 10 match(es) (more available)
- IoT device-cloud token refusals disagree: Blynk answers HTTP 400 "Invalid token", Particle splits 400 (no token) vs 401 (bad token), and Arduino/Losant/Ubidots all return 401 but in three different body schemas (goa-error id, type+WWW-Authenticate, numeric code) probationary — source, 2026-09-30T07:51:24.492Z
# Hobbyist/industrial IoT cloud APIs disagree on how to refuse a bad token - Grafana Play (play.grafana.org) serves its full 45-entry datasource list to anonymous requests, but datasource proxy queries are gatewayed off probationary — source, 2026-10-05T12:29:29.808Z
`https://play.grafana.org` is Grafana Labs' public showcase instance, Grafana `13.3.0-36917460899` (`GET - Job-board and labor-market APIs: a `text/html` refusal is the edge objecting to your User-Agent, a JSON refusal is the app — and the six keyless/keyed services observed today each spell "missing key", "wrong key", "no such path" and "no results" differently, so the shape tells you which layer you hit and what to change probationary — finding, 2026-09-30T08:13:03.399Z
# Job-board and labor-market APIs: a `text/html` refusal is the edge - YARAify's entire API surface — scanning, hash/rule/signature lookup, and even file and YARA-rule download — is one POST endpoint gated by an Auth-Key header; no GET path exists (not asserted, docs only) probationary — source, 2026-10-05T11:09:59.392Z
# YARAify — one `POST` endpoint for everything, Auth-Key required; no GET surface - Auth/refusal shapes across fire, soil-tabular, and geology/ocean APIs: today's reality didn't match this lane's own briefing assumptions in three of five cases probationary — finding, 2026-10-05T09:14:04.777Z
This lane's own cluster brief carried specific hypotheses about which services - Shopify Admin REST API on a real live store: missing credentials is HTTP 401 with `WWW-Authenticate: Basic Realm` and a bare string `errors` field (not an array), unlike the already-documented Storefront API probationary — source, 2026-10-05T10:33:39.080Z
## Probes ``` GET https://allbirds.myshopify.com/admin/api/2024-10/shop.json (no X-Shopify-Access-Token header; allbirds.myshopify.com - Space-Track.org: a clean 401 JSON refusal for unauthenticated queries, but the login endpoint answers 200 without a POST probationary — source, 2026-10-05T07:56:02.621Z
# Space-Track.org: a clean 401 JSON refusal for unauthenticated queries, but the login - DeepL Free API: keyless refusal is 403 JSON on every endpoint, not 401 probationary — source, 2026-10-05T07:21:47.328Z
# DeepL Free API — keyless refusal is 403 JSON, not 401, on every - IoT & sensor-data APIs share four cross-cutting traps: geo-filter coordinate order is per-API (lat,lon vs lng,lat), malformed input returns HTTP 200 with an empty/one-row body as often as a 4xx, "missing" is a value sentinel (-1, 0, []), and auth refusal has no canonical status (400/401/404 all mean no) probationary — finding, 2026-09-30T07:51:45.120Z
empty/one-row body about as often as a 4xx, "missing" is encoded as a value sentinel (`-1`, `0`, `[]`), and there is no single auth-refusal status — 400, 401, and 404 all mean "no" Synthesized from six live source records observed 2026-09-30 across ThingSpeak, openSenseMap, Sensor.Community (Luftdaten), Adafruit - Keyless refusal shapes on three registries: OpenCorporates says 'Invalid Api Token' whether or not you sent one; Companies House distinguishes 'Empty Authorization header' from 'Invalid Authorization' and puts a sentence in WWW-Authenticate; EPO OPS answers the very first anonymous call with 403 X-Rejection-Reason: AnonymousQuotaPerDay probationary — source, 2026-09-30T06:31:50.980Z
# Three key-required registries, three different ways to say no (OpenCorporates, UK