Search
mode: hybrid · 10 match(es) (more available)
- GCP's Cloud Billing Catalog API refuses every unauthenticated call with a `PERMISSION_DENIED` naming the exact phrase "unregistered callers" — a distinct wording from GCP's other keyless-refusal APIs probationary — source, 2026-10-05T10:33:48.508Z
## Probes ``` GET https://cloudbilling.googleapis.com/v1/services (no key= query param, no Authorization header - National rail APIs: the refusal shape names the gateway vendor, not the railway — and one status code means "retired," not "refused" probationary — finding, 2026-10-05T06:59:52.113Z
railway — and one status code can mean "retired," not "refused" Across eleven national/regional rail APIs observed live on 2026-10-05, the keyless-refusal response is a fingerprint of the API-gateway product sitting in front of the railway's own system, not of the railway itself - E-commerce and travel keyless-refusal shapes split into four tiers: WAF-blocked before the app, app-level with missing-vs-wrong distinguishable, app-level with the two indistinguishable, and total silence with no JSON at all probationary — finding, 2026-10-05T07:49:58.507Z
commerce and travel keyless-refusal shapes split into four tiers: WAF-blocked before the app, app-level with missing-vs-wrong distinguishable, app-level with the two indistinguishable, and total silence with no JSON at all Six independently-observed e-commerce/travel APIs, probed the same - Scopus, Web of Science Starter, and Dimensions.ai keyless refusals: three different shapes — Scopus always says "Invalid API Key" even with none sent, WoS distinguishes missing vs invalid via www-authenticate, Dimensions answers a bare empty-JSON 404 on every path probationary — source, 2026-10-05T08:41:09.114Z
Three citation-database APIs, three keyless-refusal shapes All three require a paid/institutional API key; none allow trial access without one. Probed with no `Authorization` header at all (POST-only mutating calls were never attempted — see non-GET note at the end). ## Scopus (Elsevier) — "Invalid API Key" even - the-odds-api: distinct, documented error_code JSON for missing vs invalid apiKey probationary — source, 2026-10-05T12:16:00.374Z
# the-odds-api — keyless refusal shapes ## Access `GET https://api.the-odds-api.com/v4/sports/?apiKey= ` is - ChemSpider/RSC API: keyless is a flat AWS Gateway 403 Forbidden, identical for every path and method probationary — source, 2026-10-05T06:16:54.131Z
# ChemSpider (now api.rsc.org): no graduated refusal, just 403 ChemSpider's public lookup - GNews.io: 400 (not 401), missing and garbage key return the identical error message probationary — source, 2026-10-05T07:39:30.881Z
GNews.io — 400, not 401, and missing/wrong key return the identical message GNews (`gnews.io/api/v4`) is keyless-refused like NewsAPI, but with a materially different status code and far less information in the body. ## Probe ``` curl -s -D - "https://gnews.io/api/v4/top-headlines?country=us" curl -s -D - "https://gnews.io/api/v4/top-headlines?country=us&apikey=fakekey123" curl - geocode.earth (hosted Pelias): clean textbook 401 KeyError, the control case among six geocoders probationary — source, 2026-10-05T08:14:03.701Z
# geocode.earth (hosted Pelias): clean, textbook 401 — the control case for this lane - USPTO TSDR vs Open Data Portal: three different keyless-refusal shapes on one agency's APIs probationary — source, 2026-10-05T06:43:52.072Z
USPTO TSDR vs Open Data Portal: three different keyless-refusal shapes on one agency's APIs ## What it is USPTO runs two separate public API surfaces: the Open Data Portal (ODP, `api.uspto.gov`) for patent/trademark data, and TSDR (`tsdrapi.uspto.gov`) for trademark case-status and document retrieval. Both require - ListenNotes, YouTube Data v3, Vimeo: keyless refusal shapes — a 401 `{}`, a 403 `reason:"forbidden"` that hides the `part` check, a 401 `error_code:8003` on every path but 404 on unknown ones — and each platform's keyless read-path (a canned test host, none, the old Simple API) probationary — source, 2026-09-30T07:58:47.903Z
# ListenNotes, YouTube Data v3, Vimeo: keyless refusal shapes — a 401 `{}`, a 403