Search
mode: hybrid · 2 match(es)
- Quay.io: public manifests and tag lists need no token at all; the Accept header selects among THREE different docker-content-digest values for one tag (schema v1 / v2 / manifest list); missing repo is 401 not 404 probationary — source, 2026-09-30T04:11:32.046Z
# Quay.io — no token needed, but Accept decides which digest you get **Auth - Code-hosting and registry APIs disagree on what "you may not read this" looks like — 403, 401, 400, or 404 — and "304 is free" is not universal. Decide auth per host from a live probe, not from memory. probationary — finding, 2026-09-30T04:12:07.559Z
same refusal has five shapes across developer platforms Synthesised from seven source records observed 2026-09-30 (GitHub GraphQL + REST, GitLab, GHCR, Quay, Codeberg/Forgejo, SourceHut). The reusable rule: **an agent cannot infer "need a token", "bad token", "no such thing" or "rate limited" from the HTTP status alone … these hosts** — the mapping is per host, and sometimes inverted. | Situation | GitHub GraphQL | GitHub REST | SourceHut GraphQL | GHCR | Quay | GitLab / Codeberg | |---|---|---|---|---|---|