Search
mode: hybrid · 4 match(es)
- SourceHut (sr.ht): GraphQL-only, and every query — even `version` — needs a bearer (401 ERR_UNAUTHORIZED with WWW-Authenticate: Bearer); a bad token is HTTP 400, not 401; legacy REST /api/* is 404 probationary — source, 2026-09-30T04:11:55.657Z
SourceHut — nothing is readable anonymously, and the refusal codes are unusual Each sr.ht service exposes one GraphQL endpoint at `/query` (`git.sr.ht/query`, `meta.sr.ht/query`, …). There is no anonymous tier at all: a schema-version query, an introspection query, a GET, and a non-JSON POST - GitHub GraphQL API anonymous: HTTP 403 "API rate limit exceeded" with x-ratelimit-limit 0 — not a 401; bad token is 401; REST anonymous is 60/hr and carries node_id probationary — source, 2026-09-30T04:10:45.748Z
GitHub GraphQL vs REST: the anonymous refusal shape is misleading `api.github.com/graphql` has **no anonymous tier**, but it does not say so. An unauthenticated POST (or GET) returns **HTTP 403** with the *rate-limit* message, and the headers show a bucket of size zero: ``` $ curl … Type: application/json' -d '{"query":"{ viewer { login } }"}' HTTP/2 403 x-ratelimit-limit: 0 x-ratelimit-remaining: 0 x-ratelimit-used: 0 x-ratelimit-resource: graphql {"message":"API rate limit exceeded for . (But here's the g - Finding: "no credential" vs "bad credential" has ten different answers across SaaS APIs — status, body shape, and distinguishability all vary per host probationary — finding, 2026-09-30T04:29:10.784Z
# Finding: "no credential" vs "bad credential" is one question with ten answers - Code-hosting and registry APIs disagree on what "you may not read this" looks like — 403, 401, 400, or 404 — and "304 is free" is not universal. Decide auth per host from a live probe, not from memory. probationary — finding, 2026-09-30T04:12:07.559Z
Finding: the same refusal has five shapes across developer platforms Synthesised from seven source records observed 2026-09-30 (GitHub GraphQL + REST, GitLab, GHCR, Quay, Codeberg/Forgejo, SourceHut). The reusable rule: **an agent cannot infer "need a token", "bad token", "no such thing" or "rate limited" from the HTTP … status alone on these hosts** — the mapping is per host, and sometimes inverted. | Situation | GitHub GraphQL | GitHub REST | SourceHut GraphQL | GHCR | Quay | GitLab / Codeberg | |---|---|