Skip to content

Authentication

There are no keys and no accounts, and what that means for a caller.

There are no API keys and there are no accounts. Nothing to sign up for, nothing to put in an Authorization header, and no identity a request is made as.

That follows from what the site is: the corpus is fetched at build time and baked into the deployment, so a read returns bytes that were already public when they were built. There is no per-caller view to protect.

Reading

Send the request. Nothing else.

curl -sS https://lateano.com/api/collections

Every read resource answers every caller identically, and none returns 401 or 403. Do not build a token store or a retry-on-401 path for them.

The one header that is nearly a credential, and is not

POST /api/feedback requires an Idempotency-Key, so a retry after a timeout cannot record the submission twice. It requires a JSON Content-Type as well; neither header identifies you.

curl -sS -X POST https://lateano.com/api/feedback \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: <a value you choose>' \
  -d '{"kind":"broken","severity":"high","message":"the tool returned nothing"}'

The 201 confirms what was recorded. A submission is never served back at any address, so the key opens nothing and is worth storing only if you intend to retry. Colin reads what arrives out of band. The two public reads are GET /api/feedback, the recent list, and QUERY /api/feedback, the ranked aggregate; neither read carries anybody’s message.

Send the same key again with the same body and the same submission is confirmed again. Send it with a different body and the request is refused with 409.

What is not enforced

There is no rate limit. A courtesy quota was designed and not built: the account it would run on has no edge rate limiting available, so nothing in this API emits 429. The problem type exists in the catalogue and no path reaches it. Do not write a back-off path expecting one; do be reasonable.

The gate you may have read about

The repository contains a soft-launch gate — a shared password in front of the whole site, served as the body of a 401. It is switched off, and it is not authentication either: it covers every route at the edge rather than any resource in particular, and were it raised it would cover this documentation too.

Nothing about it changes how you call the API. It is documented here only because the code is visible in the repository and the natural conclusion from reading it would be wrong.

One address that is not a resource

/api/cron/feedback-rollup is a scheduled job that happens to live under /api/, and it does answer 401 to a caller without the scheduler’s secret. There is nothing to call there and no key that would help. It is the one exception to the paragraph above and to the promise on Errors, which is where it is described.

---
title: "Authentication"
description: "There are no keys and no accounts, and what that means for a caller."
url: "https://lateano.com/developers/api/authentication"
author: "Colin Lateano"
---

# Authentication

There are no keys and no accounts, and what that means for a caller.

**There are no API keys and there are no accounts.** Nothing to sign up for,
nothing to put in an `Authorization` header, and no identity a request is made
as.

That follows from what the site is: the corpus is fetched at build time and baked
into the deployment, so a read returns bytes that were already public when they
were built. There is no per-caller view to protect.

## Reading

Send the request. Nothing else.

```sh
curl -sS https://lateano.com/api/collections
```

Every read resource answers every caller identically, and none returns `401` or
`403`. Do not build a token store or a retry-on-401 path for them.

## The one header that is nearly a credential, and is not

**`POST /api/feedback` requires an `Idempotency-Key`**, so a retry after a
timeout cannot record the submission twice. It requires a JSON `Content-Type`
as well; neither header identifies you.

```sh
curl -sS -X POST https://lateano.com/api/feedback \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: <a value you choose>' \
  -d '{"kind":"broken","severity":"high","message":"the tool returned nothing"}'
```

The `201` confirms what was recorded. **A submission is never served back at
any address**, so the key opens nothing and is worth storing only if you intend
to retry. Colin reads what arrives out of band. The two public reads are
`GET /api/feedback`, the recent list, and `QUERY /api/feedback`, the ranked
aggregate; neither read carries anybody's message.

Send the same key again with the same body and the same submission is confirmed
again. Send it with a different body and the request is refused with `409`.

## What is not enforced

**There is no rate limit.** A courtesy quota was designed and not built: the
account it would run on has no edge rate limiting available, so nothing in this
API emits `429`. The problem type exists in the catalogue and no path reaches it.
Do not write a back-off path expecting one; do be reasonable.

## The gate you may have read about

The repository contains a soft-launch gate — a shared password in front of the
whole site, served as the body of a `401`. **It is switched off**, and it is not
authentication either: it covers every route at the edge rather than any resource
in particular, and were it raised it would cover this documentation too.

Nothing about it changes how you call the API. It is documented here only because
the code is visible in the repository and the natural conclusion from reading it
would be wrong.

## One address that is not a resource

`/api/cron/feedback-rollup` is a scheduled job that happens to live under
`/api/`, and it does answer `401` to a caller without the scheduler's secret.
There is nothing to call there and no key that would help. It is the one
exception to the paragraph above and to the promise on
[Errors](/developers/api/errors), which is where it is described.