Does the Snyk API need an API key?

Does the Snyk API need an API key?

Yes for the 14 operations checked: an anonymous request was refused, on 2026-09-15. Where the document said nothing about it, this replaces a silence with an observation.

ERR-2026-1716, ERR-2026-1809, ERR-2026-1897, ERR-2026-1901, ERR-2026-1945, ERR-2026-2022, ERR-2026-2046, ERR-2026-2047, ERR-2026-2053, ERR-2026-2127, ERR-2026-2196, ERR-2026-2204

Why is my Snyk request rejected when I copied the example?

Because the document contradicts itself. 1 parameter in this specification declare one type and give an example, default or allowed value of another. Both statements are in the same file, so this needs no request to confirm.

ERR-2026-2269

Every record behind those answers

15 open records, observed 2026-09-10. Every claim below carries the command that disproves it. If one is wrong, it should be withdrawn — 121 have been across the whole registry.

credentials are required (observed) (14)

The document establishes no authentication requirement for this operation; an anonymous request is refused with 401. The requirement is now observed rather than unknown.

ERR-2026-1716Get organization notification settingsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1809Retrieve a single projectHTTP 401checked 2026-09-15, 2 times
ERR-2026-1897List all entitlementsHTTP 401checked 2026-09-15, 2 times
ERR-2026-1901List all organizations in a groupHTTP 401checked 2026-09-15, 2 times
ERR-2026-1945List MembersHTTP 401checked 2026-09-15, 2 times
ERR-2026-2022ListHTTP 401checked 2026-09-15, 2 times
ERR-2026-2046List all members in a groupHTTP 401checked 2026-09-15, 2 times
ERR-2026-2047View group settingsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2053List all roles in a groupHTTP 401checked 2026-09-15, 2 times
ERR-2026-2127RetrieveHTTP 401checked 2026-09-15, 2 times
ERR-2026-2196Get existing integration by typeHTTP 401checked 2026-09-15, 2 times
ERR-2026-2204Get import job detailsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2219Get an organization's entitlement valueHTTP 401checked 2026-09-15, 2 times
ERR-2026-2222List all tags in a groupHTTP 401checked 2026-09-15, 2 times

Check it yourself:

curl -sS -o /dev/null -w '%{http_code}\n' https://api.snyk.io/api/v1/org/errata-probe-not-a-real-identifier/notification-settings

a default contradicts its own declared type (1)

Parameter 'includeGroupAdmins' (in query) declares type 'boolean' and its own default is "false". A caller copying it is refused.

ERR-2026-2269List Membersno runnable checkchecked 2026-09-15, 2 times

If a record here is wrong

Run its check. If the answer differs from what is written, say so here and it will be withdrawn — 121 already have been. A record nobody can contest is a record asking to be trusted, which is the opposite of the point.

What this page does not tell you

This is not a clean bill of health for anything not listed. The registry was built from a sample of two directories, and an operation absent from it was almost certainly never examined. Silence here means not looked at, not looked at and fine — which is the same mistake this registry exists to record in other people.

What this is

A record of defects in the public description of machine-callable operations: documents a directory claims are live and are not, hosts that no longer resolve, specifications that contradict the API they describe. It is not a ranking, not a review, and not a judgement about the service. No credential is ever sent to anything listed here.

The whole registry, machine-readable: errata.json. Index of subjects: index.html.

Built from registry errata-2026-09-10@b7cb54d3a847. If manifest.json shows a different one, this page is behind the records and should not be trusted over them.