generated: '2026-09-10' method: probed source: >- Anonymous live calls to all four Forest Service API surfaces plus /.well-known/ discovery probes, 2026-09-10. note: >- All four public Forest Service API surfaces are fully anonymous. No key, token, account, registration or referrer restriction stands between a caller and a 200 — every response recorded in this repository was obtained with a bare curl and no credential of any kind. This is the single most agent-relevant fact about the estate: there is nothing to onboard to and nothing to rotate. It is also why scopes/ is deliberately absent — there is no OAuth surface to derive scopes from. summary: schemes_declared: 0 auth_required: false registration_required: false model: open public data, unauthenticated security_schemes: [] surfaces: - api: Forest Service Research Data Archive Web Service base_url: https://www.fs.usda.gov/rds/archive/webservice auth: none verified: - url: https://www.fs.usda.gov/rds/archive/webservice/efrs status: 200 detail: 200 text/xml, 32 experimental forests returned, no credential sent. - url: https://www.fs.usda.gov/rds/archive/webservice/organizations status: 200 detail: 200 text/xml, 405 organizations returned. - url: https://www.fs.usda.gov/rds/archive/webservice/oaipmh?verb=Identify status: 200 session_note: >- The service sets a PHPSESSID cookie and an F5 BIGipServer cookie on response. Neither is required on the request — the calls above were made cookieless. - api: FIADB-API / EVALIDator base_url: https://apps.fs.usda.gov/fiadb-api auth: none verified: - url: https://apps.fs.usda.gov/fiadb-api/fullreport?rselected=Land%20Use%20-%20Major&cselected=Land%20use&snum=79&wc=102020&outputFormat=NJSON status: 200 detail: >- 200 application/json, 34 KB of population estimates with standard errors, no credential sent. Response carries Access-Control-Allow-Origin "*", so the API is callable directly from a browser origin. session_note: >- Sets an evalidator.session cookie (Secure, HttpOnly) on response; not required on request. - api: FSGeodata EDW map services (ArcGIS REST) base_url: https://apps.fs.usda.gov/arcx/rest/services auth: none verified: - url: https://apps.fs.usda.gov/arcx/rest/services?f=json status: 200 - url: https://apps.fs.usda.gov/arcx/rest/services/EDW?f=json status: 200 detail: 144 MapServer services enumerated anonymously. note: >- ArcGIS Server supports token authentication, but no /arcx/tokens/generateToken challenge is raised for these services — they are published to the anonymous role. - api: FSGeodata RDW map services (ArcGIS REST, fsgisx01) base_url: https://apps.fs.usda.gov/fsgisx01/rest/services auth: none verified: - url: https://apps.fs.usda.gov/fsgisx01/rest/services?f=json status: 200 - api: U.S. Forest Service Geospatial Data Discovery (DCAT-US catalog) base_url: https://data-usfs.hub.arcgis.com auth: none verified: - url: https://data-usfs.hub.arcgis.com/api/feed/dcat-us/1.1.json status: 200 detail: 200 application/json, ~2 MB catalog returned anonymously. discovery_probes: - url: https://www.fs.usda.gov/.well-known/openid-configuration status: 404 - url: https://www.fs.usda.gov/.well-known/oauth-authorization-server status: 404 - url: https://apps.fs.usda.gov/.well-known/oauth-authorization-server status: 500 transport: https_required: true hsts: true detail: >- Every host redirects to HTTPS and returns Strict-Transport-Security max-age=31536000; www.fs.usda.gov adds includeSubDomains and preload. See security/forest-service-domain-security.yml.