Evidence-backed facts
- Records documentation lists GET /api/records/ and GET /api/records/:id, with size maxima of 25 for anonymous and 100 for authenticated searches. Its general all-requests-authenticated statement conflicts with this anonymous allowance; live anonymous access is unverified. informative
- Documented OAuth scopes separate deposit:write, which cannot publish, from deposit:actions for publication, editing and discarding edits. Tokens should remain private and travel over HTTPS in the Authorization header rather than URL parameters. informative
- The sandbox at https://sandbox.zenodo.org requires separate registration and tokens from https://zenodo.org, may be cleared at any time, and issues test DOIs under 10.5072 rather than production prefix 10.5281. informative
- For bulk access the guide recommends OAI-PMH or metadata dumps instead of search loops. OAI-PMH documents 50 records per page and two-minute resumption tokens, with expiry returning 422; metadata and file access rights must not be conflated. informative