Primary question: Are the third-party APIs a row points to still free and still live? Entries are hand-maintained, so verify each one before building.
RepoDaily adoption score
RepoDaily rates this as 93/100 (strong) for adoption: evidence, installation path, production risk, differentiation, license clarity, and AI/agent fit are scored from the article sources and adoption notes.
4 source(s) across 3 source category/categories, plus a RepoDaily-specific evidence module when available.
6 workflow step(s), 4 next-action step(s), and 3 command/install signal(s) were detected.
Trending momentum is +2,476 stars, with maintenance/release/issue signals counted when present.
Risk is marked low, with 6 security note(s) and 3 explicit skip condition(s).
3 opportunity lens item(s), 4 alternative(s), and 3 type-specific section(s) support differentiation.
License source or license wording is present.
3 AI/agent-related signal(s) were detected in the article text and metadata.
Project overview
public-apis/public-apis topped the GitHub trend chart on August 16, 2026, adding 2,476 stars in the window, and it did so without shipping a framework, a library, or a service. The repository is exactly what its description says: 'A collective list of free APIs.' Community members and staff at APILayer curate the entries by hand, and the whole catalog lives in MIT-licensed markdown you can read, copy, and fork.
The current README opens with a commercial announcement rather than the catalog itself: the APILayer unified suite, pitched as 'One Account, One Dashboard, and One API key,' covering IPstack, Marketstack, Aviationstack, Positionstack, Mediastack, Mailboxlayer, Countrylayer, Serpstack, and Scrapestack. Readers can fork the official APILayer Postman Collection, which the README claims gets you started 'in under 60 seconds.' The README also links a Discord server for updates, questions, and random community calls. The catalog proper, the tables of free APIs, sits beneath this promotion.
Calling it a 'self-hosted app' needs one clarification: there is no app to run. GitHub labels the primary language Python, but the artifact you consume is markdown tables. Self-hosting here means forking the repository and keeping a pruned copy of the list for yourself, which the MIT license (Copyright (c) 2022 public-apis) explicitly permits, including modification and sublicensing as long as the notice is retained.
What makes the list durable is its entry schema. Every API is a table row carrying five facts: the API name linked to its documentation, a description capped at 100 characters by the contribution rules, whether HTTPS is supported, whether CORS is supported, and what authentication it needs. That answers, up front, the three questions a developer would otherwise verify provider by provider.
Why it is trending now
- 2,476 stars in the trend window and the #1 rank on 2026-08-16, for a repository whose main deliverable is one markdown file.
- The README headline announcing the APILayer unified suite: one account, one dashboard, one API key across nine named products including IPstack, Marketstack, and Aviationstack.
- Run-in-Postman buttons and a forkable official collection pitched as a sub-60-second start.
- A linked Discord server offering updates, answers, and random community calls.
- A scannable table schema (API, Description, Auth, HTTPS, CORS, plus an optional Call this API column) that replaces a dozen documentation-site visits.
Problem it solves
- Finding genuinely free APIs normally means opening pricing pages one by one; the list collapses that search into table rows.
- Auth differs per provider: OAuth, an apiKey string, an X-Mashape-Key header, a User-Agent header, or nothing, and guessing wrong costs integration time.
- Browser apps fail hard on APIs without CORS; CONTRIBUTING.md states plainly that without proper CORS configuration an API is only usable server-side.
- Public API directories attract marketing submissions; the maintainers reject pull requests opened to market paid company APIs, keeping this a community tool.
How it works
- Open README.md and pick a category section; entries are alphabetically ordered within each section.
- Read the row: the API name links to its docs, the description is capped at 100 characters, and the Auth, HTTPS, and CORS columns give the deciding facts.
- Interpret Auth from a fixed vocabulary: OAuth, apiKey, X-Mashape-Key, No, or User-Agent.
- Interpret CORS as Yes, No, or Unknown; No means the API must be called from a server, not a browser page.
- If a row carries a Call this API link, fork the Postman collection listed there; the APILayer suite has an official collection linked from the README.
- To self-host, fork the repository under MIT terms, delete the categories you have not vetted, and keep the copyright notice from LICENSE.
What the repo actually contains: one file and a schema
The catalog is a set of alphabetically ordered markdown tables in README.md. Each row follows the format fixed in CONTRIBUTING.md: | API | Description | Auth | HTTPS | CORS | Call this API |. The documented example entry is NASA ('NASA data, including imagery') with Auth marked No, HTTPS Yes, and CORS Yes. The description must not exceed 100 characters, and each table column is padded with one space on either side.
Two columns are closed vocabularies. Auth accepts exactly five values: OAuth, apiKey, X-Mashape-Key, No, and User-Agent. CORS accepts Yes, No, or Unknown. The Call this API column links a Postman collection when one exists. The files that matter are README.md (the catalog), CONTRIBUTING.md (the schema and rules), and LICENSE (MIT).
How to try it in one sitting
- Open README.md, jump to a category section, and read the tables; every API name links straight to its documentation.
- Filter first on Auth and CORS: rows with Auth = No and CORS = Yes need no keys and can be called from a browser page.
- For the promoted APILayer suite, fork the official Postman collection linked in the README, which claims a start in under 60 seconds.
- To self-host: fork the repository, remove every category you have not verified, and retain the MIT copyright notice from LICENSE.
Curation rules, and where the list can go stale
- One link per pull request, PR titles in the format 'Add Api-name API' (the documented example: 'Add Blockchain API'), and commits squashed before review.
- Descriptions capped at 100 characters and alphabetical order enforced per section.
- Marketing-driven PRs are rejected in writing; an API must have full free access or at least a free tier, and must not require purchasing a device or service before it works.
- New versions of an already-listed API are not accepted as separate entries; CONTRIBUTING.md notes the old version gets deprecated.
- Nothing in the source pack shows automated liveness checks, so a row can outlive the endpoint it points to.
Who should pay attention?
Good fit if
- Hackathon and demo work that needs a free data source picked within minutes.
- A team forking the MIT-licensed tables and pruning them into an internal API shortlist.
- Browser-side projects where the CORS column pre-filters which APIs can be called directly.
Skip for now if
- Production services needing SLAs, support contracts, or uptime guarantees; the repo links providers, it does not operate them.
- Anyone needing machine-readable OpenAPI specs rather than human-readable markdown.
- Projects that cannot absorb a third-party API disappearing or moving behind a paywall.
Risks and cautions
The repository ships text under an MIT license; nothing installs or executes. The real risk sits downstream, at each third-party provider a row points to.
- No runtime: the deliverables are README.md, CONTRIBUTING.md, and LICENSE.
- The MIT license (Copyright (c) 2022 public-apis) permits copying, modifying, and sublicensing with the notice retained.
- Rows link to external providers whose pricing, keys, or availability can change without any signal appearing in this repo.
- Curation is manual, one link per PR with 100-character description caps, and no automated liveness verification appears in the source pack.
- The repository itself requests no credentials and executes nothing; exposure begins when you call a listed provider.
- The Auth column names the credential model up front: OAuth, apiKey, an X-Mashape-Key header, a User-Agent header, or No.
- The HTTPS column marks transport security row by row.
- The CORS column separates browser-callable APIs from server-side-only ones, per the explicit warning in CONTRIBUTING.md.
- CONTRIBUTING.md rejects APIs that depend on buying a device or service before use.
- Rate limits, terms of service, and key storage remain each provider's own documentation to check.
Alternatives to compare
| Approach | When to use | Trade-off |
|---|---|---|
APILayer | You want a single vendor with one account, one dashboard, and one API key across geocoding, email validation, flight, and stock-data APIs. | Commercial plans; promoted directly in the README. |
RapidAPI Hub | You want a marketplace that unifies billing, keys, and usage analytics across many providers. | Freemium with per-API subscriptions. |
free-for-dev | You want free tiers across SaaS generally, not only HTTP APIs. | Free, community-maintained. |
OpenAPI Directory (APIs.guru) | You need machine-readable OpenAPI specs to generate clients from, instead of markdown tables. | Free and open source. |
What this trend reveals
Fork it into an internal catalog
The MIT license explicitly grants use, copy, modify, and sublicense rights. Prune the tables down to the providers your team has verified and host the result next to internal docs.
Keep the LICENSE copyright notice in your fork, then delete every category you have not vetted.
Query the schema before writing client code
Auth and CORS are closed vocabularies, so shortlisting is mechanical: rows with Auth = No and CORS = Yes run in a browser with zero setup, while rows with CORS = No need a server hop.
Pick one category section, copy the rows where Auth = No and CORS = Yes, and fire one request each from a browser console.
Add your own liveness layer
CONTRIBUTING.md notes that old API versions get deprecated, so rows can point at retired endpoints. A fork with a scheduled check turns static markdown into a monitored catalog.
On your fork, script a weekly request against each listed endpoint and flag the rows that stop answering.
RepoDaily verdict
An MIT-licensed shortcut for finding free APIs, held together by a strict five-column schema. Fork it, filter on Auth and CORS, and verify every provider yourself before building.