The State of Public APIs 2026: Data From 1,580 APIs
Quick answer: Of the 1,580 public APIs live in our directory on 9 October 2026, 40% need no authentication, 51% need an API key and 9% need OAuth. Only 15% are both keyless and CORS-enabled, so you can call them straight from a browser. Newer APIs are more locked down: 67% of those added since 2023 need a key. 5.3% currently fail our link checker.
Most "state of APIs" reports are surveys of what developers say they do. This one is a census of what public APIs actually are. We run a directory of public APIs, every entry carries its auth method and CORS support, and a link checker probes every listed URL. Every number below comes from that table, pulled the day this was published.
How do public APIs authenticate in 2026?
| Authentication | APIs | Share | |---|---|---| | None (keyless) | 625 | 39.6% | | API key | 798 | 50.5% | | OAuth | 150 | 9.5% | | Other (a marketplace key header or a required User-Agent) | 7 | 0.4% |
Half of all public APIs want an API key, and only one in ten wants OAuth. That matches what we see in practice: a key in a header or query string is the cheapest way for a provider to count and throttle you, while OAuth only appears where an API acts on a user's account. If you are deciding how to protect your own API, our guide to API authentication methods walks through the trade-offs.
How many public APIs work from a browser?
CORS decides whether front-end JavaScript on another domain may read the response.
| CORS support | APIs | Share | |---|---|---| | Yes | 605 | 38.3% | | No | 147 | 9.3% | | Unknown (not yet verified) | 828 | 52.4% |
The honest headline is the last row: for more than half of public APIs, nobody has recorded whether a browser can call them. Our CORS field comes from the listing, not from probing every endpoint, so treat "unknown" as "test it before you build on it".
The browser-ready set is small: 241 APIs (15.3%) are both keyless and CORS-enabled. That is the pool you can prototype against from a static page with no backend and no secret to leak. Open-Meteo is the archetype. It is also the slice we sampled when we read real cache headers for our API caching survey.
Every one of the 1,580 listed URLs uses HTTPS, so HTTPS no longer separates one public API from another.
Are new APIs harder to access than old ones?
Yes, clearly. Splitting the directory by when an API was listed:
| Auth | Listed in 2022 (1,096 APIs) | Added since 2023 (484 APIs) | |---|---|---| | None | 44.0% | 29.5% | | API key | 43.2% | 67.1% | | OAuth | 12.3% | 3.1% |
Keyless APIs fell from 44% of the 2022 catalogue to 30% of additions since 2023, and API keys took their place. OAuth shrank too, from 12% to 3%. New APIs are less often consumer platforms (where OAuth lives) and more often developer services that meter usage per key.
The newer cohort is also better documented: 60.5% of APIs added since 2023 declare CORS support, against 28.5% of the 2022 listings, where 64% are still "unknown".
Which categories are growing?
The directory spans 52 categories. The largest today are Development (162 APIs), Geocoding (91), Games & Comics (88), Government (87), Finance (70) and Transportation (67).
Additions per year: 81 in 2023, 119 in 2024, 118 in 2025, and 166 so far in 2026, already the biggest year since the directory launched. The pace roughly doubled in August and September 2026 (30 and 29 new APIs, against 12 to 16 a month earlier in the year).
The 2026 additions skew towards building, not browsing: Development (25), Finance (17), Sports & Fitness (9) and AI (7) lead.
Where do keyless APIs still live?
Keyless share varies enormously by category (categories with at least 20 APIs):
| Most keyless | Keyless | Most locked down | Keyless | |---|---|---|---| | Books | 82% | Shopping | 0% | | Science & Math | 79% | AI | 6% | | Health | 78% | Business | 8% | | Government | 75% | Documents & Productivity | 12% | | Test Data | 70% | Photography | 12% |
The pattern is funding. Public-sector and community data (Government, Books, Health) is paid for upstream and given away. Commercial data, and anything that costs GPU time, is metered. NASA and Gutendex need no key; every AI API but two in our directory does.
OAuth is concentrated, not spread out. It is required by 60% of Social APIs, 47% of Shopping APIs and 36% of Music APIs, where calls act on a user's account: Reddit, Spotify, Shopify. Outside those three categories it is rare.
How many public APIs are dead?
Our link checker probes every listed URL weekly, gives blocked or slow responses a second opinion from a real browser, and re-checks failures daily. On 8 October 2026, 84 live listings (5.3%) were failing:
- 62 returned an HTTP error page
- 11 sat on a domain that no longer resolves
- 6 timed out, 3 had broken TLS, 2 failed to connect
Most of them are not blips: 50 of the 84 have failed 75 checks in a row.
Age predicts it. 6.7% of APIs listed in 2022 are failing today, against 2.3% of those added since 2023. And the failing listings are only the tail of a bigger churn: of the 2,034 APIs ever published in the directory, 454 (22.3%) have since been archived, removed as dead, duplicated or delisted. For the 2022 cohort that figure is 25.8%. Roughly one in four public APIs from four years ago is gone.
Auth method barely matters for survival: 5.3% of keyless APIs, 5.8% of key-based and 3.3% of OAuth APIs are currently failing.
What does this mean if you depend on public APIs?
- Assume you will need a key. Two in three new APIs require one. Keep keys server-side, which also sidesteps CORS.
- Verify CORS yourself. For half the catalogue it is unrecorded.
- Plan for the API to disappear. A one-in-four four-year attrition rate means any free dependency needs a fallback. Cache aggressively and keep an alternative bookmarked from the same category.
- Watch your quota. Key-based APIs throttle per key; our rate limiting guide covers the headers to read.
Methodology
Snapshot of the production dr_pa_resources table taken 9 October 2026. Scope: rows in the public APIs directory with status = published and archived = false, 1,580 APIs. Auth and CORS come from each listing's structured fields. Category is each API's primary category. "Listed in 2022" means a published_at date in 2022 (1,060 of those 1,096 arrived with the directory's launch import on 14 February 2022). Link health is the latest result of our link checker, which last re-checked every failing row on 8 October 2026. The archived rate uses all 2,034 APIs ever published. We will refresh these numbers monthly.
Frequently asked questions
What percentage of public APIs require an API key?
In our directory of 1,580 public APIs, 50.5% require an API key, 9.5% require OAuth and 39.6% require no authentication at all. Among APIs added since 2023, the API key share rises to 67%.
Are there free APIs that need no API key?
Yes, 625 of the APIs we list need no key. They cluster in public-sector and community data: books, science, health and government. 241 of them also allow CORS, so they work directly from browser JavaScript. Browse Open Data for a good starting set.
How many public APIs stop working?
About one in four. Of the APIs listed in 2022, 25.8% have since been archived and another 6.7% currently fail our link checker. Newer APIs fare better so far, at 2.3% failing.
Which API category is growing fastest in 2026?
Development, with 25 new APIs this year, followed by Finance (17), Sports & Fitness (9) and AI (7). 2026 is already the directory's biggest year for additions since its 2022 launch.