Yes for the 14 operations checked: an anonymous request was refused, on 2026-09-15. Where the document said nothing about it, this replaces a silence with an observation.
ERR-2026-1745, ERR-2026-1787, ERR-2026-1806, ERR-2026-1842, ERR-2026-1984, ERR-2026-1988, ERR-2026-2009, ERR-2026-2023, ERR-2026-2077, ERR-2026-2111, ERR-2026-2143, ERR-2026-2147
14 open records, observed 2026-09-10. Every claim below carries the command that disproves it. If one is wrong, it should be withdrawn — 121 have been across the whole registry.
The document establishes no authentication requirement for this operation; an anonymous request is refused with 401. The requirement is now observed rather than unknown.
ERR-2026-1745 | Get events | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1787 | Get new in-app messages for account | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1806 | Get unread in-app messages for account | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1842 | Get user properties | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1984 | Get new in-app messages for user | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1988 | Get user segments | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2009 | Get in-app messages for user | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2023 | Get account segments | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2077 | Get in-app messages for account | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2111 | Get account properties | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2143 | Get snippet for a website | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2147 | Get unread in-app messages for user | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2192 | Validate API key | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2209 | List in-app messages | HTTP 401 | checked 2026-09-15, 2 times |
Check it yourself:
curl -sS -o /dev/null -w '%{http_code}\n' https://api.journy.io/events
Run its check. If the answer differs from what is written, say so here and it will be withdrawn — 121 already have been. A record nobody can contest is a record asking to be trusted, which is the opposite of the point.
This is not a clean bill of health for anything not listed. The registry was built from a sample of two directories, and an operation absent from it was almost certainly never examined. Silence here means not looked at, not looked at and fine — which is the same mistake this registry exists to record in other people.
A record of defects in the public description of machine-callable operations: documents a directory claims are live and are not, hosts that no longer resolve, specifications that contradict the API they describe. It is not a ranking, not a review, and not a judgement about the service. No credential is ever sent to anything listed here.
The whole registry, machine-readable: errata.json. Index of subjects: index.html.
Built from registry errata-2026-09-10@b7cb54d3a847. If manifest.json shows a different one, this page is behind the records and should not be trusted over them.