Does the SIGNL4 API need an API key?

Does the SIGNL4 API need an API key?

Yes for the 18 operations checked: an anonymous request was refused, on 2026-09-15. Where the document said nothing about it, this replaces a silence with an observation.

ERR-2026-1674, ERR-2026-1677, ERR-2026-1678, ERR-2026-1680, ERR-2026-1681, ERR-2026-1683, ERR-2026-1684, ERR-2026-1686, ERR-2026-1687, ERR-2026-1690, ERR-2026-1691, ERR-2026-1692

Why does SIGNL4 return 401 when its spec declares no authentication?

Because the document is wrong about it. Its OpenAPI description declares no security requirement for 18 operations, and an anonymous request to each was refused with 401 on 2026-09-15. An agent trusting the document plans a call that cannot work.

ERR-2026-1674, ERR-2026-1677, ERR-2026-1678, ERR-2026-1680, ERR-2026-1681, ERR-2026-1683, ERR-2026-1684, ERR-2026-1686, ERR-2026-1687, ERR-2026-1690, ERR-2026-1691, ERR-2026-1692

Every record behind those answers

18 open records, observed 2026-09-10. Every claim below carries the command that disproves it. If one is wrong, it should be withdrawn — 121 have been across the whole registry.

the document declares no authentication and the API demands it (18)

The OpenAPI document declares no security requirement for this operation. An anonymous request is refused with 401. An agent trusting the document plans a call that cannot work.

ERR-2026-1674Get event parametersHTTP 401checked 2026-09-15, 2 times
ERR-2026-1677Get your subscription's current prepaid settings.HTTP 401checked 2026-09-15, 2 times
ERR-2026-1678Get all categoriesHTTP 401checked 2026-09-15, 2 times
ERR-2026-1680Get alert notificationsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1681Get your subscription's current prepaid balance.HTTP 401checked 2026-09-15, 2 times
ERR-2026-1683Get a specific categoryHTTP 401checked 2026-09-15, 2 times
ERR-2026-1684Get metrics for a specific categoryHTTP 401checked 2026-09-15, 2 times
ERR-2026-1686Get attachments of an alertHTTP 401checked 2026-09-15, 2 times
ERR-2026-1687Get category subscriptionsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1690Get your subscription's prepaid transactions.HTTP 401checked 2026-09-15, 2 times
ERR-2026-1691Get overview eventHTTP 401checked 2026-09-15, 2 times
ERR-2026-1692Get Alert ReportHTTP 401checked 2026-09-15, 2 times
ERR-2026-1693Gets the names of all alert category images. You can get the image by going to account.sigHTTP 401checked 2026-09-15, 2 times
ERR-2026-1695Gets a specified attachment of a specified alert.HTTP 401checked 2026-09-15, 2 times
ERR-2026-1699Get AlertHTTP 401checked 2026-09-15, 2 times
ERR-2026-1702Get an overview alert.HTTP 401checked 2026-09-15, 2 times
ERR-2026-1703Get metrics for all categoriesHTTP 401checked 2026-09-15, 2 times
ERR-2026-1707Get annotations of an alertHTTP 401checked 2026-09-15, 2 times

Check it yourself:

curl -sS -o /dev/null -w '%{http_code}\n' https://connect.signl4.com/api/events/errata-probe-not-a-real-identifier/parameters

If a record here is wrong

Run its check. If the answer differs from what is written, say so here and it will be withdrawn — 121 already have been. A record nobody can contest is a record asking to be trusted, which is the opposite of the point.

What this page does not tell you

This is not a clean bill of health for anything not listed. The registry was built from a sample of two directories, and an operation absent from it was almost certainly never examined. Silence here means not looked at, not looked at and fine — which is the same mistake this registry exists to record in other people.

What this is

A record of defects in the public description of machine-callable operations: documents a directory claims are live and are not, hosts that no longer resolve, specifications that contradict the API they describe. It is not a ranking, not a review, and not a judgement about the service. No credential is ever sent to anything listed here.

The whole registry, machine-readable: errata.json. Index of subjects: index.html.

Built from registry errata-2026-09-10@b7cb54d3a847. If manifest.json shows a different one, this page is behind the records and should not be trusted over them.