generated: '2026-07-25' method: searched source: >- https://www.acma.gov.au/sites/default/files/2019-11/Spectrum%20licensing%20API.docx docs: - https://www.acma.gov.au/sites/default/files/2019-11/Spectrum%20licensing%20API.docx - https://www.donotcall.gov.au/getmedia/9810ca84-d7af-4972-b626-6b5495f52ac2/DNCR-SOAP-Fact-Sheet.pdf - https://www.donotcall.gov.au/industry/washing-process-overview/sftp summary: types: - none - soap-body-credentials - ssh-key - session api_key_in: [] oauth2_flows: [] note: >- ACMA publishes no OAuth 2.0, OpenID Connect or API-key scheme on any public surface. Its open register API is genuinely unauthenticated; its gated services carry credentials in the SOAP body or over SSH rather than in HTTP auth headers. schemes: - name: none api: acma:spectrum-licensing type: none description: >- The ACMA Spectrum Licensing API requires no authentication at all — no API key, no account, no registration, no Authorization header. Every one of the 22 REST operations and the SOAP endpoint answers anonymous requests. Verified live on 2026-07-25 against api.acma.gov.au/SpectrumLicensingAPIOuterService/OuterService.svc: all documented operations returned HTTP 200 with data on an anonymous request. Access is instead governed contractually, by the "Licence to use the Register of Radiocommunications Licences" terms, and technically by a 2,000-record cap per query. sources: - openapi/acma-spectrum-licensing-openapi.yml - wsdl/acma-spectrum-licensing.wsdl evidence: verified_live: https://api.acma.gov.au/SpectrumLicensingAPIOuterService/OuterService.svc/CategoryListJSON verified_status: 200 verified_on: '2026-07-25' - name: dncr-rta-account-credentials api: acma:do-not-call-register-washing type: soap-body-credentials description: >- The Do Not Call Register Real Time Access washing service authenticates with an account identifier and passphrase passed as SOAP method parameters, not as HTTP credentials. Every published operation takes TelemarketerId (the Account ID) and TelemarketerPassword; WashOnlyUserId is supplied only when the wash is performed under a wash-only sub-account of the main administration account. Multi-factor authentication is NOT required on the real-time channel, but the passphrase used must match the passphrase set when MFA was configured on the account. Access additionally requires a paid washing subscription of type D or above. parameters: - name: TelemarketerId required: true description: The Account ID issued to the industry account holder. - name: TelemarketerPassword required: true description: The account passphrase; must match the passphrase used when setting up MFA on the account. - name: WashOnlyUserId required: false description: Supplied only when washing under a wash-only sub-account of the main account. transport: tls_minimum: TLSv1.2 note: >- ACMA states users are required to have TLS 1.2 to connect, and that client applications must be configured to force TLS 1.2 or above. sources: - wsdl/acma-dncr-realtime-washing.wsdl - https://www.donotcall.gov.au/getmedia/9810ca84-d7af-4972-b626-6b5495f52ac2/DNCR-SOAP-Fact-Sheet.pdf - name: dncr-sftp-ssh-key api: acma:do-not-call-register-washing type: ssh-key description: >- The Automated Washing Service batch channel authenticates over SFTP at sftp.donotcall.gov.au. Access seekers first connect with a username and a password issued by SMS to the registered mobile number, then upload an RSA public key (SSH-2 RSA, 2048-bit) into the account's /upload folder; subsequent connections use the key pair. Access is provisioned by emailing DNCR support with the organisation name, contact, mailing address, email, mobile number and the external public IP address of the device that will connect — the service is IP-restricted. host: sftp.donotcall.gov.au directories: - upload - download - archive sources: - https://www.donotcall.gov.au/industry/washing-process-overview/sftp - https://www.donotcall.gov.au/getmedia/9b201a6a-6426-414a-a48d-0fdee2608ae1/dncr-ssh-key-authentication.pdf - name: azure-apim-portal-signin api: null type: session description: >- The ACMA developer portal at developer.acma.gov.au is a Microsoft Azure API Management developer portal behind a complete sign-in wall. Every anonymous request — /apis, /products, /api-docs — returns the identical sign-in shell, and the portal management API /mapi/apis returns HTTP 401. No API, product or specification is visible without an account. The /.well-known/openid-configuration and /.well-known/oauth-authorization-server paths return HTTP 200 but serve text/html (the SPA catch-all), not OIDC or RFC 8414 metadata, so no discoverable authorization server exists. sources: - well-known/acma-well-known.yml evidence: probed: https://developer.acma.gov.au/.well-known/openid-configuration status: 200 content_type: text/html verdict: SPA sign-in shell, not OIDC metadata verified_on: '2026-07-25' - name: numbering-system-session api: null type: session description: >- The ACMA Numbering System at thenumberingsystem.com.au is an authenticated web application for licensed carriage service providers. Its internal JSON backend under /app/* returns HTTP 401 to anonymous callers and is not offered or documented as an API. sources: - review.yml