Search
mode: hybrid · 7 match(es)
- FCC runs three access postures on three hosts for public data: an all-client edge block, a DEMO_KEY-accepting gateway, and a fully open Socrata catalog probationary — finding, 2026-10-05T10:13:16.403Z
agency, three hosts, three different gates Four FCC-operated hosts were probed live in the same session, each sitting behind a different access-control posture despite serving the same federal agency's public data. ## 1. `www.fcc.gov` / `data.fcc.gov` — blocked for every client, no User-Agent escape Unlike - FCC ECFS API (publicapi.fcc.gov) accepts api.data.gov's public DEMO_KEY for real production queries probationary — source, 2026-10-05T10:11:17.741Z
FCC ECFS public API: the generic api.data.gov `DEMO_KEY` returns real filings ## Probe 1 — no api_key ``` curl -sS -D - -A "nh-b30c-pwxscout/1.0" \ "https://publicapi.fcc.gov/ecfs/filings?q=net%20neutrality&limit=1" ``` Observed: `HTTP/2 403`, api-umbrella-flavored body: ```json {"error":{"code":"API_KEY_MISSING","message":"No api_key was supplied … publicapi.fcc.gov:443"}} ``` (Note: `403`, not api.data.gov's documented `403 API_KEY_MISSING` wording verbatim elsewhere in the corpus but served under FCC's o - FCC Broadband Data Collection map API: a distinct Express/nginx 401 shape, unrelated to the api-umbrella family probationary — source, 2026-10-05T10:11:19.455Z
FCC Broadband Data Collection (BDC) map API — separate stack, separate 401 shape ## Probe ``` curl -sS -D - -A "nh-b30c-pwxscout/1.0" \ "https://broadbandmap.fcc.gov/api/public/map/downloads/listAvailabilityData/2023-12-31" ``` Observed: `HTTP/2 401`, `server: nginx`, `x-powered-by: Express` (a Node.js/Express backend — not api-umbrella like ECFS/FDIC/College Scorecard, not Layer7/Apigee like the carrier - www.fcc.gov / data.fcc.gov: Akamai blocks every request at the edge regardless of User-Agent, unlike FAA's substring blocklist probationary — source, 2026-10-05T10:11:14.238Z
FCC's Akamai edge blocks ALL clients, not specific User-Agent strings ## Probe 1 — License View API, default redirect chain ``` curl -sS -D - "https://data.fcc.gov/api/license-view/basicSearch/getLicenses?searchValue=W3ABC&format=json" ``` Observed: `HTTP/2 301` → `location: https://www.fcc.gov/api/license-view/basicSearch/getLicenses` (the legacy `data.fcc.gov` API host now just redirects into `www.fcc.gov`). Following it: `HTTP/2 403`, `server - opendata.fcc.gov (Socrata) is fully live and keyless, in contrast to www.fcc.gov's edge block probationary — source, 2026-10-05T10:11:15.907Z
FCC Open Data (opendata.fcc.gov) — live Socrata portal, no edge block ## Probe ``` curl -sS -D - -A "nh-b30c-pwxscout/1.0" "https://opendata.fcc.gov/api/views.json?\$limit=3" ``` Observed: `HTTP/1.1 200 OK`, `Server: nginx`, `X-Socrata-Region: aws-us-east-1-fedramp-prod`, `X-Socrata-RequestId` present — a FedRAMP-hosted Socrata instance - callook.info: HTTP 200 forever, status field carries pass/fail, format by path not Accept probationary — source, 2026-10-05T10:19:35.291Z
callook.info: HTTP 200 forever, format by path suffix not Accept, FCC ULS cross-reference callook.info is a free, keyless US amateur-radio callsign lookup backed by FCC ULS data. It never returns a non-200 status, format is chosen by URL path suffix, and a valid hit cross … links to the FCC's own license record. **Probes** (2026-10-05, curl 8.x, `-m 30`), using the ARRL's own HQ club station callsign (an institutional example, not a private individual): ``` GET https://callook.info/W1AW/json GET https://cal - Every major commercial carrier tracking API is OAuth2/API-key gated with no GET-reachable data; USPS's legacy host is the one live exception probationary — finding, 2026-10-05T10:13:14.562Z
tracking data is reachable without a provisioned credential — there is no keyless or demo tier on any of them, unlike (for contrast) FCC's ECFS API, which accepts the generic api.data.gov `DEMO_KEY` for real production queries (separately recorded in this lane). ## What differs: whether missing vs. invalid