Does the BBC iPlayer Business Layer API need an API key?

Does the BBC iPlayer Business Layer API need an API key?

Not for the 5 operations checked. An anonymous request was answered with a machine-readable body that is not an error envelope, on 2026-09-15. That says nothing about rate limits, about cost, or about any other operation.

ERR-2026-1682, ERR-2026-1689, ERR-2026-1697, ERR-2026-1701, ERR-2026-1706

Why is my BBC iPlayer Business Layer request rejected when I copied the example?

Because the document contradicts itself. 7 parameters in this specification declare one type and give an example, default or allowed value of another. Both statements are in the same file, so this needs no request to confirm.

ERR-2026-2245, ERR-2026-2246, ERR-2026-2247, ERR-2026-2248, ERR-2026-2249, ERR-2026-2250, ERR-2026-2251

Every record behind those answers

12 open records, observed 2026-09-10. Every claim below carries the command that disproves it. If one is wrong, it should be withdrawn — 121 have been across the whole registry.

an allowed value contradicts the declared type (7)

Parameter 'mixin' (in query) declares type 'array' and its enum contains a value of another type.

ERR-2026-2245Get episodes by group, brand or seriesno runnable checkchecked 2026-09-15, 2 times
ERR-2026-2246List the highlights for a channel.no runnable checkchecked 2026-09-15, 2 times
ERR-2026-2247Get programme highlightsno runnable checkchecked 2026-09-15, 2 times
ERR-2026-2248Get programmes popularno runnable checkchecked 2026-09-15, 2 times
ERR-2026-2249List the highlights for a category.no runnable checkchecked 2026-09-15, 2 times
ERR-2026-2250Get broadcasts by channelno runnable checkchecked 2026-09-15, 2 times
ERR-2026-2251Episode for a given pid.no runnable checkchecked 2026-09-15, 2 times

usable with no account (observed) (5)

An anonymous request is answered with a machine-readable response. The operation is reachable with no account. This says nothing about whether the result is useful, or about rate limits.

ERR-2026-1682List all regionsHTTP 200checked 2026-09-15, 2 times
ERR-2026-1689List all the channels.HTTP 200checked 2026-09-15, 2 times
ERR-2026-1697Get statusHTTP 200checked 2026-09-15, 2 times
ERR-2026-1701Get categoriesHTTP 200checked 2026-09-15, 2 times
ERR-2026-1706Get schemaHTTP 200checked 2026-09-15, 2 times

Check it yourself:

curl -sS -o /dev/null -w '%{http_code}\n' https://ibl.api.bbci.co.uk/ibl/v1/regions

If a record here is wrong

Run its check. If the answer differs from what is written, say so here and it will be withdrawn — 121 already have been. A record nobody can contest is a record asking to be trusted, which is the opposite of the point.

What this page does not tell you

This is not a clean bill of health for anything not listed. The registry was built from a sample of two directories, and an operation absent from it was almost certainly never examined. Silence here means not looked at, not looked at and fine — which is the same mistake this registry exists to record in other people.

What this is

A record of defects in the public description of machine-callable operations: documents a directory claims are live and are not, hosts that no longer resolve, specifications that contradict the API they describe. It is not a ranking, not a review, and not a judgement about the service. No credential is ever sent to anything listed here.

The whole registry, machine-readable: errata.json. Index of subjects: index.html.

Built from registry errata-2026-09-10@b7cb54d3a847. If manifest.json shows a different one, this page is behind the records and should not be trusted over them.