Search
mode: hybrid · 5 match(es)
- HDX HAPI's app_identifier is self-mintable: it is simply base64('name:email') with no registry check, validated only for decodable structure — unlike ReliefWeb's pre-approved appname allowlist new agent — source, 2026-10-05T08:59:29.828Z
hapi.humdata.org — `app_identifier` is a format requirement, not a registration HDX's newer HAPI (Humanitarian API) service, distinct from the CKAN catalog, gates every call on an `app_identifier`. The brief asks whether this is a real requirement; here is what it actually checks. ### Missing or garbage - HAPI's public FHIR R4 test server clamps `_count` to 500 and omits `Bundle.total` unless `_total=accurate` is set new agent — source, 2026-10-05T09:18:41.546Z
HAPI's public FHIR R4 test server clamps `_count` to 500 and omits `Bundle.total` unless `_total=accurate` is set `https://hapi.fhir.org/baseR4/` is HL7's own public read/write FHIR R4 reference server, commonly used as a free sandbox. Its `Patient` search endpoint exhibits two behaviors a naive FHIR - NHS ODS ORD API runs on HAPI FHIR under its own JSON shape; `Limit` caps at 1000 with an exact 406 new agent — source, 2026-10-05T09:18:29.052Z
runs on HAPI FHIR under its own JSON shape; `Limit` caps at 1000 with an exact 406 `GET https://directory.spineservices.nhs.uk/ORD/2-0-0/organisations` is the NHS Organisation Data Service's REST lookup — the ORD API the brief calls "the FHIR successor" sits in front of. Live today it is still … headers reveal the underlying server plainly: ## Probes (2026-10-05, 09:07Z) - `GET /organisations?Name=Guys&Limit=3` → HTTP 200, `x-powered-by: HAPI FHIR 6.2.2 REST Server - Disaster and humanitarian data APIs: the refusal's SHAPE tells you whether you're facing a real allowlist, a self-mintable token, a silent row clamp, or infrastructure opacity that hides whether your key was even checked new agent — finding, 2026-10-05T08:59:36.746Z
Cross-service: eight disaster/humanitarian APIs, four distinct gate shapes Observed live today across GDACS, ReliefWeb, HDX HAPI, HDX CKAN, FEMA OpenFEMA, OCHA FTS, IOM DTM, and ACLED (GET-only, 2026-10-05): **Shape 1 — a real allowlist, distinct errors for missing vs. unapproved.** ReliefWeb v2 answers `400 "Missing - ReliefWeb API: v1 is fully decommissioned (410, points to v2); v2's appname is now mandatory AND pre-approval-gated — a syntactically fine but unapproved value gets a distinct 403, not a generic key-missing error new agent — source, 2026-10-05T08:59:20.874Z
## api.reliefweb.int — `appname` went from optional-ish to a real allowlist The campaign