Observed Signal · Jul 8, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Positive
Ten Keyless Government APIs for Data Pipelines
Aleksei Spinov published a verified list of 10 government and intergovernmental APIs that return JSON without an API key or signup, re-checked via live curl on July 6, 2026. The roundup covers money and fiscal endpoints (USAspending, Treasury FiscalData), regulatory and publication feeds (Federal Register), health and clinical data (openFDA, PubMed E-utilities, ClinicalTrials.gov, CDC/Socrata), and global science/data services (GBIF, USGS Earthquakes, World Bank). The article emphasizes practical pitfalls: HTTP 200 can carry deprecated, empty, or stale bodies; response shapes and query parameters (format, pagination, bracketed params) vary and must be parsed correctly; and some services enforce polite User-Agent, throttles, or per‑IP limits. The piece includes rejected examples (REST Countries, Census redirecting to a missing-key page) and actionable notes on rate limits, parsing traps, and licensing.
Practical, developer-focused resource listing authoritative, keyless government APIs and concrete parsing/capacity pitfalls useful for data pipelines and analytics; helpful but not industry-shifting.
Track Real-Time Infrastructure Signals & Market Shifts
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- The author re-verified each listed endpoint once with a live curl on July 6, 2026 (HTTP 200 and a real response body).
- The ten keyless APIs listed are: USAspending; Treasury FiscalData; Federal Register; openFDA; PubMed E-utilities (NCBI); ClinicalTrials.gov v2; CDC via Socrata (data.cdc.gov); GBIF; USGS Earthquakes; and the World Bank Indicators API.
- openFDA unauthenticated limits: 240 requests per minute and 1,000 per day per IP; a free key raises the daily limit to 120,000.
- PubMed E-utilities enforce a keyless limit of 3 requests per second per IP (a free key raises that to 10 per second); many endpoints return XML by default unless a format parameter (e.g., retmode=json or format=geojson) is provided.
- Examples of failure modes: REST Countries returned HTTP 200 with a deprecated body; US Census redirected (HTTP 302) to a missing-key page; CDC Socrata dataset returned a 200 with data frozen in 2023.
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Audit finds ~20% of popular public APIs broken
A developer audit monitored 99 free public APIs with hourly HTTP checks and found widespread degradation across large community-maintained API lists. The author ran checks on Cloudflare's free tier (Workers + D1), produced daily JSON snapshots and a static site (freeapi.watch) with 30-day uptime metrics and a graveyard of dead APIs. From the sample data the author estimates roughly 15–25% of entries on large community API lists are degraded (dead, paid, moved, or heavily rate-limited). The post lists several prominently discoverable APIs that are dead or paywalled as of mid-2026 and recommends discovery, verification, and monitoring before integrating public APIs.
Normalizing Seven Government Recall Feeds
An engineer describes normalising 176,000 product-recall records from seven public government sources (EU Safety Gate, France's RappelConso, CPSC, NHTSA and FDA/openFDA among them) into a single queryable corpus. The piece details practical engineering challenges: differing source granularities and how they affect deduplication decisions; mining identifiers from free-text fields and validating GTIN check digits; undocumented pagination caps (openFDA 'skip' limit of 25,000) that silently truncate results; large decompressed payloads (device enforcement expanded to ~252 MiB) that broke Cloudflare Workers isolates; V8 string-slicing retention causing memory bloat; and the importance of detecting undocummented amendments by hashing content per record. The corpus is available via recallproven.com as an API and dated, checksummed export.
Complete API Security Checklist: Defense-in-Depth
This technical guide (published 2026-06-22) presents a defense-in-depth checklist for securing APIs, covering authentication and authorization, token management (JWT/OAuth2), TLS everywhere, strict input validation, rate limiting, secrets management, logging/monitoring, vulnerability scanning mapped to the OWASP API Security Top 10 (2023), and incident response playbooks. The article includes production-ready code/config snippets (Node/Express examples), recommends using dedicated secrets managers (HashiCorp Vault, AWS/GCP secret managers), centralizing controls at an API gateway, and maintaining an explicit API inventory with versioning and deprecation timelines. It also cites multiple industry reports (Salt Security, Akamai, Imperva, Cloudflare) that highlight the high prevalence and impact of API incidents and secret leaks.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
