# authorship: API Evangelist. Not published by the University of Pittsburgh.
x-method: derived
x-authorship: >-
Written by API Evangelist from live probes of the University of Pittsburgh's own public
surfaces. Pitt publishes no equivalent document. The `method:` key below is the university
pipeline's provenance vocabulary (how we came to hold the facts); x-method above is the
authorship vocabulary the provenance manifest reads (who wrote the file).
generated: '2026-08-30'
method: probed
source: >-
Live error probes of https://www.tycho.pitt.edu/api, https://data.wprdc.org/api/3/action,
https://anthro-age.pitt.edu/ojs/anthro-age and https://d-scholarship.pitt.edu on 2026-08-30. The
University of Pittsburgh publishes no error reference for any of these surfaces; every entry
below is an observed response, not a documented one.
provider: University of Pittsburgh
providerId: university-of-pittsburgh
apis:
- aid: university-of-pittsburgh:project-tycho
operator: institution
envelope:
shape: 'Plain HTML fragment, no envelope'
content_type: text/html
note: >-
Project Tycho returns errors as an HTML sentence with HTTP 200 and no machine-readable
structure — no code, no field, no JSON. Successful calls return text/csv. A client cannot
distinguish success from failure by status code or content type alone without parsing the
body.
errors:
- status: 200
message: 'Invalid API key. Please see the API Help (https://www.tycho.pitt.edu/dataset/api) for more information.'
trigger: The apikey query parameter is missing, malformed or not recognised.
evidence:
url: https://www.tycho.pitt.edu/api/condition?apikey=INVALIDKEY
status: 200
note: >-
This is the important one, and it has two failure modes stacked on each other. First, a
rejected credential is served with HTTP 200, so anything branching on response.ok treats it as
a success. Second, the key is checked BEFORE the path is routed: /api/nonsensepath?apikey=INVALIDKEY
returns byte-identical output to /api/condition?apikey=INVALIDKEY, so an unauthenticated
caller cannot tell a real endpoint from a typo, and no path in this API can be verified
without a credential.
- status: 200
message: 'No results'
trigger: >-
A /query call whose offset exceeds the number of rows in the result set. Documented in the
published API reference.
note: >-
A bare text string rather than an empty CSV body, so a CSV parser reading the response gets a
single malformed row rather than zero rows.
documented_error_reference: false
documented_error_reference_note: >-
https://www.tycho.pitt.edu/dataset/api/ documents parameters and examples but contains no error
section, no status-code table and no error catalogue.
- aid: university-of-pittsburgh:wprdc-ckan
operator: institution
envelope:
shape: '{"help": "", "success": , "error": {"__type": "", "message": ""}}'
content_type: application/json
note: >-
The CKAN Action API envelope. This is CKAN's contract, not Pitt's engineering — recorded here
because it is what a caller of data.wprdc.org actually receives, and because it is the one
surface in this profile that carries its status in a structured field and in the HTTP status
line at the same time.
errors:
- status: 200
message: 'success: true with an empty result set'
trigger: A well-formed package_search that matches nothing.
note: CKAN reports "no matches" as a successful search with count 0, not as an error.
- status: 404
message: '{"success": false, "error": {"__type": "Not Found Error"}}'
trigger: An unknown action name or an unknown package id.
documented_error_reference: false
documented_error_reference_note: >-
WPRDC publishes no error reference of its own; callers are left to CKAN's upstream documentation.
- aid: university-of-pittsburgh:uls-ejournal-oai
operator: institution
envelope:
shape: ''
content_type: text/xml
note: >-
OAI-PMH 2.0's own error model. Protocol errors are returned inside a valid OAI-PMH envelope
with HTTP 200, which is the protocol behaving correctly rather than a defect.
errors:
- status: 403
message: '{"error":"api.403.unauthorized","errorMessage":"You are not authorized to access the requested resource."}'
trigger: Any unauthenticated call to the OJS REST API at /api/v1/*.
evidence:
url: https://anthro-age.pitt.edu/ojs/anthro-age/api/v1/issues
status: 403
note: >-
Correct behaviour, and worth contrasting with Project Tycho on the same campus: OJS returns a
real 403 with a stable machine-readable error code, where Tycho returns 200 with prose.
documented_error_reference: false
- aid: university-of-pittsburgh:d-scholarship-oai
operator: tenant
vendor: Hyku Commons (Samvera Hyku)
envelope:
shape: ' on the live path; Cloudflare interstitial HTML on the stale one'
content_type: text/xml
note: >-
Two different failure surfaces live on the same hostname, and telling them apart is the whole
finding here. https://d-scholarship.pitt.edu/catalog/oai — the current Hyku endpoint — answers
HTTP 200 with conformant OAI-PMH. https://d-scholarship.pitt.edu/cgi/oai2 — the stale EPrints
path from before the migration — answers HTTP 403 behind a Cloudflare challenge.
errors:
- status: 403
message: 'Just a moment...'
trigger: >-
Any automated request to the repository's HTML surface or to the stale /cgi/oai2 path,
including one carrying a full browser User-Agent and navigation headers.
evidence:
url: https://d-scholarship.pitt.edu/cgi/oai2?verb=Identify
status: 403
note: >-
A Cloudflare bot challenge, not an application error. The June 2026 profile read this as bot
protection over a working endpoint; it is in fact a dead path, and the working endpoint at
/catalog/oai was one path away and answered 200 on the first try. The lesson is the pipeline's
own: read the body, and probe the alternative before concluding a surface is blocked.
- status: 200
message: '...'
trigger: An unrecognised verb or a missing required argument on /catalog/oai.
evidence:
url: https://d-scholarship.pitt.edu/catalog/oai?verb=Identify
status: 200
note: >-
OAI-PMH 2.0's own error model, returned by blacklight_oai_provider. Protocol errors travel
inside a valid envelope with HTTP 200 — correct protocol behaviour, and the vendor's
implementation rather than Pitt's.
documented_error_reference: false
cross_cutting_observations:
- >-
Four surfaces, four unrelated error models, no shared envelope and no shared vocabulary. There is
no institution-wide error convention at the University of Pittsburgh because there is no
institution-wide API program — each surface was built by a different unit (Public Health Dynamics
Laboratory, UCSUR, University Library System) and inherits the error model of whatever software it
runs on.
- >-
Not one of the four publishes an error reference. The only error documentation of any kind found
on a pitt.edu host is the single sentence Project Tycho returns in the error body itself.