Why can't I reach the mastercard.com API?

Why can't I reach the mastercard.com API?

Its declared address answered neither a request nor a TLS handshake on 2026-09-15, across 14 cases. This is a weaker finding than a host that does not exist: a server can be temporarily down.

ERR-2026-0525, ERR-2026-0526, ERR-2026-0527, ERR-2026-0528, ERR-2026-0529, ERR-2026-0530, ERR-2026-0531, ERR-2026-0532, ERR-2026-0533, ERR-2026-0534, ERR-2026-0535, ERR-2026-0536

Every record behind those answers

14 open records, observed 2026-09-10. Every claim below carries the command that disproves it. If one is wrong, it should be withdrawn — 121 have been across the whole registry.

the document refuses machine access (14)

The declared provider origin exists but refuses an unauthenticated machine request.

ERR-2026-0525https://developer.mastercard.com/devzone/api/portal/swagger/bin-table-resourceHTTP 401checked 2026-09-15, 2 times
ERR-2026-0526https://developer.mastercard.com/devzone/api/portal/swagger/bill-payment-validatorHTTP 401checked 2026-09-15, 2 times
ERR-2026-0527https://developer.mastercard.com/devzone/api/portal/swagger/currency-conversion-calculatorHTTP 401checked 2026-09-15, 2 times
ERR-2026-0528https://developer.mastercard.com/devzone/api/portal/swagger/locationsHTTP 401checked 2026-09-15, 2 times
ERR-2026-0529https://developer.mastercard.com/devzone/api/portal/swagger/matchHTTP 401checked 2026-09-15, 2 times
ERR-2026-0530https://developer.mastercard.com/devzone/api/portal/swagger/automatic-billing-updater-abuHTTP 401checked 2026-09-15, 2 times
ERR-2026-0531https://developer.mastercard.com/devzone/api/portal/swagger/mdes-customer-serviceHTTP 401checked 2026-09-15, 2 times
ERR-2026-0532https://developer.mastercard.com/devzone/api/portal/swagger/merchant-identifierHTTP 401checked 2026-09-15, 2 times
ERR-2026-0533https://developer.mastercard.com/devzone/api/portal/swagger/payment-account-reference-inquHTTP 401checked 2026-09-15, 2 times
ERR-2026-0534https://developer.mastercard.com/devzone/api/portal/swagger/personalized-offersHTTP 401checked 2026-09-15, 2 times
ERR-2026-0535https://developer.mastercard.com/devzone/api/portal/swagger/mastercard-repowerHTTP 401checked 2026-09-15, 2 times
ERR-2026-0536https://developer.mastercard.com/devzone/api/portal/swagger/spendingpulseHTTP 401checked 2026-09-15, 2 times
ERR-2026-0537https://developer.mastercard.com/devzone/api/portal/swagger/mastercard-merchant-presented-HTTP 401checked 2026-09-15, 2 times
ERR-2026-0538https://developer.mastercard.com/devzone/api/portal/swagger/open-banking-connect-payment-iHTTP 401checked 2026-09-15, 2 times

Check it yourself:

curl -sS -o /dev/null -w '%{http_code}\n' https://developer.mastercard.com/devzone/api/portal/swagger/bin-table-resource

Also filed as: mastercard.com:BINTableResource, mastercard.com:BillPay, mastercard.com:CurrencyConversionCalculator, mastercard.com:Locations, mastercard.com:MATCH, mastercard.com:MAWS, mastercard.com:MDES, mastercard.com:MerchantIdentifier. One page, because two sweeps named the same subject differently and the record that mattered was on the page nobody would open.

If a record here is wrong

Run its check. If the answer differs from what is written, say so here and it will be withdrawn — 121 already have been. A record nobody can contest is a record asking to be trusted, which is the opposite of the point.

What this page does not tell you

This is not a clean bill of health for anything not listed. The registry was built from a sample of two directories, and an operation absent from it was almost certainly never examined. Silence here means not looked at, not looked at and fine — which is the same mistake this registry exists to record in other people.

What this is

A record of defects in the public description of machine-callable operations: documents a directory claims are live and are not, hosts that no longer resolve, specifications that contradict the API they describe. It is not a ranking, not a review, and not a judgement about the service. No credential is ever sent to anything listed here.

The whole registry, machine-readable: errata.json. Index of subjects: index.html.

Built from registry errata-2026-09-10@b7cb54d3a847. If manifest.json shows a different one, this page is behind the records and should not be trusted over them.