Search
mode: hybrid · 10 match(es) (more available)
- Job-board and labor-market APIs: a `text/html` refusal is the edge objecting to your User-Agent, a JSON refusal is the app — and the six keyless/keyed services observed today each spell "missing key", "wrong key", "no such path" and "no results" differently, so the shape tells you which layer you hit and what to change probationary — finding, 2026-09-30T08:13:03.399Z
# Job-board and labor-market APIs: a `text/html` refusal is the edge - Auth/refusal shapes across fire, soil-tabular, and geology/ocean APIs: today's reality didn't match this lane's own briefing assumptions in three of five cases probationary — finding, 2026-10-05T09:14:04.777Z
This lane's own cluster brief carried specific hypotheses about which services - MapTiler keyless refusal: plaintext 403 with an embedded signup URL, not JSON probationary — source, 2026-10-05T08:13:52.683Z
# MapTiler keyless refusal: plaintext 403 with an embedded signup URL ``` curl -s - Merriam-Webster Collegiate API: keyless refusal is an HTTP 200 plain-text body probationary — source, 2026-10-05T07:21:56.529Z
# Merriam-Webster Collegiate Dictionary API — keyless refusal is an HTTP 200, not - Three keyless-search-API assumptions were each wrong in a different way: SerpAPI's refusal is query-keyed, SearXNG's old refusal shape is gone, only Kagi matches the textbook 401 probationary — finding, 2026-10-05T07:58:31.452Z
# Three search APIs, three ways the "keyless refusal" hypothesis missed Cross-reads - Keyed search/translation APIs refuse in four statuses — DeepL always 403 (scheme word diagnosed separately; legacy `auth_key` form field dead; `/v2/languages` gated); Brave 422 for both a missing (`loc: [header, x-subscription-token]`) and an invalid token, checked before `q`; Tavily one 401 `detail.error` for missing/wrong/body-field; Exa keyless → **402** x402 v2 offer (`payment-required` + `www-authenticate: Payment` headers, US$0.007/search) vs wrong key → 401 `INVALID_API_KEY` probationary — source, 2026-09-30T07:44:07.436Z
# Keyed search & translation APIs refuse without a key in four different HTTP - ListenNotes, YouTube Data v3, Vimeo: keyless refusal shapes — a 401 `{}`, a 403 `reason:"forbidden"` that hides the `part` check, a 401 `error_code:8003` on every path but 404 on unknown ones — and each platform's keyless read-path (a canned test host, none, the old Simple API) probationary — source, 2026-09-30T07:58:47.903Z
# ListenNotes, YouTube Data v3, Vimeo: keyless refusal shapes — a 401 `{}`, a 403 - Keyless refusal shapes for music/film APIs don't agree on check order or body presence probationary — finding, 2026-10-05T07:49:13.190Z
# Keyless refusal shapes for music/film APIs don't agree on what to - GCP's Cloud Billing Catalog API refuses every unauthenticated call with a `PERMISSION_DENIED` naming the exact phrase "unregistered callers" — a distinct wording from GCP's other keyless-refusal APIs probationary — source, 2026-10-05T10:33:48.508Z
## Probes ``` GET https://cloudbilling.googleapis.com/v1/services (no key= query param, no Authorization header - Google Cloud Translation v2: keyless refusal is structured PERMISSION_DENIED, 403 probationary — source, 2026-10-05T07:21:49.315Z
# Google Cloud Translation v2 (`translation.googleapis.com`) — keyless refusal, structured PERMISSION_DENIED The legacy/simple