# ApiVault > ApiVault is a free, open-source directory of public APIs — a searchable > catalog of 1,454 APIs across 51 categories (verified 2026-09-04), each > recorded with its authentication style, CORS support and HTTPS availability. > Run by Exastudio (formerly Exifly) at apivault.dev, licensed CC BY-NC-ND 4.0. > The read half of its own API is anonymous and unmetered. Generated by API Evangelist on 2026-09-04. ApiVault does not publish an llms.txt of its own — https://apivault.dev/llms.txt returned 404 on that date. This file is a third-party profile, not a provider document. ## API The API base is https://api.apivault.dev — note this is NOT stated in the provider's own OpenAPI, which ships no servers[] block. It was established by live observation. - [OpenAPI 3.0.3 (live)](https://api.apivault.dev/api/schema/): the provider's own drf-spectacular document. 17 paths, 18 operations, 11 schemas. - [Swagger UI](https://api.apivault.dev/api/schema/swagger-ui/): the only API reference ApiVault publishes. There is no prose documentation site. ## Anonymous operations (no credential required, all confirmed 200) - `GET /api/count` — total catalog size. - `GET /api/all` — the entire catalog in one unpaginated array. - `GET /api/categories` — the 51 categories with their integer ids. - `GET /api/categories/trending` — categories with api_count. - `GET /api/category/{category_name}` — APIs in one category, by NAME. - `GET /api/search?query=` — free-text search. The `query` parameter is ABSENT from the published spec; it is observed in the provider's own client. - `GET /api/random` — a random selection. - `GET /api/detail/{id}` — one record. ## Authenticated operations (SimpleJWT bearer) There is no API key and no client-credentials grant. A token can only be obtained by a human signing in with Google and exchanging the result at `POST /api/auth/google/`. An unattended agent cannot self-provision. - `POST /api/create` — submit an API for moderation. IRREVERSIBLE and NOT idempotent; a retry creates a duplicate. - `POST /api/interaction/like/{api_id}` / `DELETE` the same path — like and unlike. The only reversible write. - `POST /api/interaction/feedback` — message the team. No retract. - `GET /api/my_api`, `GET /api/pending/my_api`, `GET /api/auth/user/`. ## Artifacts in this profile - openapi/_original/apivault-openapi.yml — the provider's document, verbatim. - openapi/apivault-api-openapi.yml — the same, plus the observed servers[] block. - overlays/apivault-openapi-overlay.yaml — API Evangelist's enhancements. - authentication/apivault-authentication.yml — the JWT/Google-only auth model. - conventions/apivault-conventions.yml — pagination (none), idempotency (none), reversibility, tracing (none), versioning. - errors/apivault-problem-types.yml — the observed error envelope. Not RFC 9457. - data-model/apivault-data-model.yml — API, Category, Like, SafeUser and the read/write type change on `category`. - lifecycle/apivault-lifecycle.yml — versioning and the absent status page. - changelog/apivault-changelog.yml — from GitHub Releases. - conformance/apivault-conformance.yml — standards asserted and denied. - rate-limits/apivault-rate-limits.yml — limit_count 0, measured. - plans/apivault-plans-pricing.yml — plan_count 0; the service is free. - packages/apivault-packages.yml — no first-party SDK, and the npm name collisions that must not be mistaken for one. - mcp/apivault-mcp.yml — no MCP server exists; a candidate tool surface. - well-known/apivault-well-known.yml — no /.well-known/ surface on either host. - skills/ — three packaged agent skills grounded in real operationIds. ## Notable gaps (measured, not asserted) - No /.well-known/ document of any kind on apivault.dev or api.apivault.dev. - No apis.json. An API directory that is not itself machine-discoverable. - No pagination: GET /api/all returns all 1,454 records at once. - No rate-limit headers and no documented limits. - No 4xx/5xx responses declared anywhere in the published OpenAPI. - An unknown category name returns HTTP 500 with an HTML body, not 404 JSON. - No status page. https://apivault.dev/status is nginx stub_status output. - No SDK, no CLI, no MCP server, no agent card, no webhooks or event surface. - The catalog records no machine-readable contract for the APIs it lists. ## Source - [Website](https://apivault.dev/) - [Repository](https://github.com/exa-studio/ApiVault) - [Releases](https://github.com/exa-studio/ApiVault/releases) - [Privacy policy](https://apivault.dev/privacy-policy) - [Cookie policy](https://apivault.dev/cookie-policy) - [Contributors](https://apivault.dev/contributors) - [Issues](https://github.com/exa-studio/ApiVault/issues)