It depends on the operation. Of those checked on 2026-09-15, 19 refused an anonymous request and 2 answered one. An API being partly open is exactly what a single security declaration cannot express.
ERR-2026-1734, ERR-2026-1769, ERR-2026-1810, ERR-2026-1826, ERR-2026-1838, ERR-2026-1843, ERR-2026-1936, ERR-2026-1954, ERR-2026-1998, ERR-2026-2008, ERR-2026-2039, ERR-2026-2048
21 open records, observed 2026-09-10. Every claim below carries the command that disproves it. If one is wrong, it should be withdrawn — 121 have been across the whole registry.
The document establishes no authentication requirement for this operation; an anonymous request is refused with 401. The requirement is now observed rather than unknown.
ERR-2026-1734 | Returns a list of bulk send batch summaries. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1769 | Gets a list of brands. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1810 | Get a list of past due invoices. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1826 | Gets payment information for one or more payments. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1838 | Retrieves the account provisioning information for the account. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1843 | Retrieves the account information for the specified account. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1936 | Returns downgrade plan information for the specified account. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1954 | Gets billing payment information for a specific payment. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-1998 | Retrieves a billing invoice. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2008 | Gets list of recurring and usage charges for the account. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2039 | Gets the status of a specific bulk send batch. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2048 | Get a List of Billing Invoices | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2071 | Exports a brand. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2110 | Get Account Billing Plan | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2135 | Get credit card information | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2144 | Gets bulk send lists. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2167 | Returns a branding resource file. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2187 | Gets envelopes from a specific bulk send batch. | HTTP 401 | checked 2026-09-15, 2 times |
ERR-2026-2215 | Returns metadata about the branding resources for an account. | HTTP 401 | checked 2026-09-15, 2 times |
Check it yourself:
curl -sS -o /dev/null -w '%{http_code}\n' https://www.docusign.net/restapi/v2.1/accounts/errata-probe-not-a-real-identifier/bulk_send_batch
An anonymous request is answered with a machine-readable response. The operation is reachable with no account. This says nothing about whether the result is useful, or about rate limits.
ERR-2026-1772 | Retrieves the available REST API versions. | HTTP 200 | checked 2026-09-15, 2 times |
ERR-2026-1977 | Lists resources for REST version specified | HTTP 200 | checked 2026-09-15, 2 times |
Check it yourself:
curl -sS -o /dev/null -w '%{http_code}\n' https://www.docusign.net/restapi/service_information
Run its check. If the answer differs from what is written, say so here and it will be withdrawn — 121 already have been. A record nobody can contest is a record asking to be trusted, which is the opposite of the point.
This is not a clean bill of health for anything not listed. The registry was built from a sample of two directories, and an operation absent from it was almost certainly never examined. Silence here means not looked at, not looked at and fine — which is the same mistake this registry exists to record in other people.
A record of defects in the public description of machine-callable operations: documents a directory claims are live and are not, hosts that no longer resolve, specifications that contradict the API they describe. It is not a ranking, not a review, and not a judgement about the service. No credential is ever sent to anything listed here.
The whole registry, machine-readable: errata.json. Index of subjects: index.html.
Built from registry errata-2026-09-10@b7cb54d3a847. If manifest.json shows a different one, this page is behind the records and should not be trusted over them.