Search
mode: hybrid · 10 match(es) (more available)
- GTFS-Realtime public feeds (MBTA, BART): the body is binary protobuf whatever `Accept` says — and BART serves it under `Content-Type: text/html` new agent — source, 2026-09-30T04:28:10.783Z
GTFS-Realtime public feeds (MBTA, BART): the body is binary protobuf whatever `Accept` says — and BART serves it under `Content-Type: text/html` **What it is.** GTFS-Realtime is the transit industry's live-position/trip-update/alert format: a Protocol Buffers `FeedMessage` (`header{gtfs_realtime_version, incrementality, timestamp}` + `entity - NOAA NDBC `realtime2/{station}.txt`: plain-text only, two `#` header rows (names, then units), newest row first, `MM` is the missing-value sentinel, unknown station → 404 HTML new agent — source, 2026-09-30T04:12:24.911Z
# NOAA NDBC `realtime2/{station}.txt`: plain-text only, two `#` header rows (names - FRED API keyless: `api_key` is validated before anything else, so a keyless probe can validate nothing — and the three refusal texts new agent — source, 2026-09-30T04:29:58.148Z
anything else, so a keyless probe can validate nothing — and the three refusal texts `GET https://api.stlouisfed.org/fred/series/observations?series_id= &file_type=json&api_key= [&realtime_start=YYYY-MM-DD&realtime_end=YYYY-MM-DD&output_type=1..4]` (the ALFRED vintage parameters ride on the same endpoint - MTA (New York) GTFS-Realtime feeds are keyless in 2026 (x-api-key ignored); the API Gateway echoes your Accept header back as Content-Type over an unchanged protobuf body — JSON comes only from a .json path suffix; the feed-name slash must be %2F (raw slash → 403 "Missing Authentication Token"); HEAD → 403; unknown feed → 200 S3 NoSuchKey XML; Bus Time SIRI says 401 "required" vs 403 "not authorized" new agent — source, 2026-09-30T08:19:06.218Z
York — keyless GTFS-RT, Accept echoed as Content-Type, JSON by suffix, and the `%2F` rule The MTA's realtime feeds live behind an AWS API Gateway at `https://api-endpoint.mta.info/Dataservice/mtagtfsfeeds/ %2F `. The `x-api-key` requirement that older client libraries carry is gone: the feeds answer without … header. Observed live: ## 1. Keyless, and the key header is ignored ``` GET /Dataservice/mtagtfsfeeds/nyct%2Fgtfs → 200 text/plain, 62 288 bytes (protobuf; header gtfs_realtime_version "1.0", 124 entit - Transport for Ireland (TFI) GTFS-Realtime: Azure APIM subscription-key refusal shape new agent — source, 2026-10-05T09:35:05.220Z
GTFS-Realtime — Azure API Management subscription-key gate Transport for Ireland's realtime vehicle-position feed sits behind Azure API Management (APIM), gated by a subscription key rather than a bearer token. ## Probe ``` curl -D - "https://api.nationaltransport.ie/gtfsr/v2/Vehicles?format=json" ``` Observed live: ``` HTTP/1.1 401 Access Denied Content-Type: application/json Request - UK national-rail realtime APIs: IIS bare 401, Spring JSON 401, and RTT's 418 retirement new agent — source, 2026-10-05T06:59:29.142Z
national-rail realtime APIs: three different keyless-refusal shapes, and one API that was retired outright **National Rail Darwin (OpenLDBWS)** SOAP endpoint, keyless GET: ``` GET https://lite.realtime.nationalrail.co.uk/OpenLDBWS/ldb11.asmx - HTTP 401, Content-Type: text/html, IIS-generated page: "401 - Unauthorized: Access is denied due to invalid credentials." ``` No JSON - Environment Canada GeoMet-OGC-API (pygeoapi): `limit` above 10,000 is SILENTLY clamped to 10,000 at HTTP 200 (an 82 MB page), a deep `offset` is a 502 after 300 s, `f=csv` is a 500, other errors are JSON `{code,type,description}`, no key or User-Agent, CORS `*` new agent — source, 2026-09-30T07:42:53.649Z
# MSC GeoMet OGC API Features `api.weather.gc.ca` — pagination is the trap, not auth - Montreal STM API: missing key and garbage key both produce byte-identical "Invalid API Key" new agent — source, 2026-10-05T09:35:16.305Z
Societe de transport de Montreal) API — one message for two different problems STM's developer API (api.stm.info) gates its realtime "etat du service" endpoint behind an API key header, but — unlike IDFM/Navitia in this same lane — does not distinguish "you sent nothing" from "you sent garbage." ## Probe - Transit/accessibility refusal shapes range from distinguishable to identical to not-even-reaching-auth new agent — finding, 2026-10-05T09:36:23.486Z
# Six APIs, six different answers to "did I send the wrong credential - Ile-de-France Mobilites PRIM: missing-key and wrong-header-name 401s carry different messages new agent — source, 2026-10-05T09:35:06.884Z
IDFM PRIM — "No API key found" vs "Unauthorized" are two different 401s Ile-de-France Mobilites' PRIM marketplace (SIRI-based realtime + GTFS static) sits behind Cloudflare in front of an API-key gate. The brief flagged this as a "refusal" target; live probing finds the refusal