Does the ExaVault API need an API key?

Does the ExaVault API need an API key?

Yes for the 18 operations checked: an anonymous request was refused, on 2026-09-15. Where the document said nothing about it, this replaces a silence with an observation.

ERR-2026-1725, ERR-2026-1738, ERR-2026-1796, ERR-2026-1922, ERR-2026-1932, ERR-2026-1933, ERR-2026-1947, ERR-2026-1976, ERR-2026-1996, ERR-2026-2007, ERR-2026-2014, ERR-2026-2041

Why is my ExaVault request rejected when I copied the example?

Because the document contradicts itself. 2 parameters in this specification declare one type and give an example, default or allowed value of another. Both statements are in the same file, so this needs no request to confirm.

ERR-2026-2261, ERR-2026-2262

Every record behind those answers

20 open records, observed 2026-09-10. Every claim below carries the command that disproves it. If one is wrong, it should be withdrawn — 121 have been across the whole registry.

credentials are required (observed) (18)

The document establishes no authentication requirement for this operation; an anonymous request is refused with 401. The requirement is now observed rather than unknown.

ERR-2026-1725Preview a fileHTTP 401checked 2026-09-15, 2 times
ERR-2026-1738Get activity logsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1796Get individual email groupHTTP 401checked 2026-09-15, 2 times
ERR-2026-1922Get a list of all resourcesHTTP 401checked 2026-09-15, 2 times
ERR-2026-1932Get webhook logsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1933Get account settingsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1947Download a fileHTTP 401checked 2026-09-15, 2 times
ERR-2026-1976Get form data entries for a receiveHTTP 401checked 2026-09-15, 2 times
ERR-2026-1996Get Resource PropertiesHTTP 401checked 2026-09-15, 2 times
ERR-2026-2007Get receive folder form settingsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2014Get resource metadataHTTP 401checked 2026-09-15, 2 times
ERR-2026-2041Get receive folder form by IdHTTP 401checked 2026-09-15, 2 times
ERR-2026-2057Get all email groupsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2087List contents of folderHTTP 401checked 2026-09-15, 2 times
ERR-2026-2179Get notification detailsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2201Get info for a userHTTP 401checked 2026-09-15, 2 times
ERR-2026-2210Get a list of usersHTTP 401checked 2026-09-15, 2 times
ERR-2026-2225Get a list of notificationsHTTP 401checked 2026-09-15, 2 times

Check it yourself:

curl -sS -o /dev/null -w '%{http_code}\n' https://accountname.exavault.com/api/v2/resources/preview

a default contradicts its own declared type (2)

Parameter 'resume' (in query) declares type 'boolean' and its own default is "true". A caller copying it is refused.

ERR-2026-2261Upload a fileno runnable checkchecked 2026-09-15, 2 times
ERR-2026-2262Upload a fileno runnable checkchecked 2026-09-15, 2 times

If a record here is wrong

Run its check. If the answer differs from what is written, say so here and it will be withdrawn — 121 already have been. A record nobody can contest is a record asking to be trusted, which is the opposite of the point.

What this page does not tell you

This is not a clean bill of health for anything not listed. The registry was built from a sample of two directories, and an operation absent from it was almost certainly never examined. Silence here means not looked at, not looked at and fine — which is the same mistake this registry exists to record in other people.

What this is

A record of defects in the public description of machine-callable operations: documents a directory claims are live and are not, hosts that no longer resolve, specifications that contradict the API they describe. It is not a ranking, not a review, and not a judgement about the service. No credential is ever sent to anything listed here.

The whole registry, machine-readable: errata.json. Index of subjects: index.html.

Built from registry errata-2026-09-10@b7cb54d3a847. If manifest.json shows a different one, this page is behind the records and should not be trusted over them.