# XGuard Universal Paid AI Agent + Secretless Gateway API

**Canonical:** https://apis.io/apis/xguardgate-com/xguard-universal-paid-agent-api/  
**Provider:** XGuard — https://apis.io/providers/xguardgate-com/  
**Base URL:** https://api.xguardgate.com  
**Documentation:** https://xguardgate.com/developers

XGuard Universal Paid AI Agent + Secretless Gateway API is one of 4 APIs that [XGuard](https://apis.io/providers/xguardgate-com/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. Tagged areas include Agents, x402, Web Extraction, Feed Aggregation, and Credential Broker. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

The REST surface behind every XGuard product, published as OpenAPI 3.1.0 (info.version 5.1.0, 47 paths, 49 operations, servers[] https://api.xguardgate.com) at https://api.xguardgate.com/openapi.json. The Outcomes group is the canonical product: POST /v1/execute (operationId xguardExecute) takes an intent plus up to three public URLs, returns a free result for intent:demo or supplied HTML, and otherwise answers HTTP 402 with a Payment-Required header, a signed five-minute X-XGuard-Quote and an exact USDC price; a funded x402 v2 client signs and retries the identical body, and GET /v1/results/{payment_identifier} recovers a paid outcome with the original quote. The contract also carries the x402 facilitator relay (/supported, /verify, /settle, /discovery/*), the compatible paid xguard.web.fetch tool with a Base Sepolia testnet twin, the Secretless Egress operator and agent endpoints under /v1/egress/*, the Action Rail permit/execute pair under /v1/actions/*, the free ATS-100 transaction-safety test, ProofRail proof verification and health/readiness probes. Only one operation declares an operationId and no securitySchemes are declared; credentials are documented as headers (X-XGuard-Key, Payment-Signature, X-XGuard-Quote, X-XGuard-Credit) and a scoped capability token instead.

## Operations (49)

| Method | Path | Summary |
|---|---|---|
| POST | `/v1/execute` | Execute a public-source outcome |
| GET | `/supported` | Return x402 payment kinds supported by healthy upstream facilitators |
| POST | `/verify` | Firewall-check and verify an x402 payment payload |
| POST | `/settle` | Firewall-check, route and settle an x402 payment with replay protection and reconciliation |
| GET | `/healthz` | Control-plane and upstream health |
| GET | `/v1/receipts/{receipt_id}` | Read a durable XGuard settlement receipt |
| GET | `/v1/protocols` | Discover XGuard protocol-neutral control-plane capabilities |
| POST | `/v1/inspect` | Classify and policy-check an agent transaction without forwarding it |
| POST | `/v1/test` | Free Agent Transaction Safety Test across x402, MPP, AP2, UCP, ACP and MCP |
| GET | `/v1/test/schema` | Describe the free Agent Transaction Safety Test |
| POST | `/edge/{merchant-host}/{path}` | Proxy a DNS-authorized merchant transaction through XGuard |
| GET | `/facilitator` | Machine-readable XGuard facilitator identity and routing capabilities |
| GET | `/discovery/resources` | List x402 Bazaar resources reachable through XGuard catalogs |
| GET | `/discovery/search` | Search x402 Bazaar resources reachable through XGuard |
| GET | `/v1/facilitator/route` | Inspect the route XGuard would select for a network/scheme |
| GET | `/v1/actions` | Discover XGuard Action Rail |
| POST | `/v1/actions/permits` | Prepare one signed single-use AI action permit |
| POST | `/v1/actions/execute` | Execute the exact request bound to an XGuard action permit |
| GET | `/v1/actions/pricing` | Action Rail Usage Credit billing boundary |
| GET | `/v1/actions/stats` | Action Rail execution and billing counters |
| GET | `/v1/egress` | Discover XGuard Secretless Egress |
| POST | `/v1/egress/credentials` | Store an encrypted upstream credential (operator only) |
| GET | `/v1/egress/credentials` | List operator credential metadata |
| POST | `/v1/egress/capabilities` | Issue a short-lived scoped capability for an agent |
| DELETE | `/v1/egress/capabilities/{id}` | Revoke a capability; already dispatched work may finish |
| POST | `/v1/egress/fetch` | Execute one credential-backed outbound request using an XGuard capability |
| GET | `/v1/egress/pricing` | Secretless Egress Usage Credit boundary |
| GET | `/v1/capabilities` | List executable outcomes and exact pricing |
| GET | `/v1/pricing` | — |
| GET | `/v1/preflight` | Describe the free guarded-request preflight |
| POST | `/v1/preflight` | Preflight a guarded paid request without contacting the target |
| POST | `/v1/pricing/quote` | Quote a live outcome or the compatible web.fetch tool |
| POST | `/v1/tools/web.fetch` | Fetch a public HTTPS resource only after required x402 settlement |
| POST | `/v1/tools/web.fetch/testnet` | Base Sepolia testnet form of xguard.web.fetch |
| GET | `/v1/operations/{payment_identifier}` | Read a payment/execution state |
| GET | `/v1/health` | Liveness probe |
| GET | `/v1/ready` | Dependency readiness probe |
| GET | `/v1/payment/readiness` | Inspect production and test payment readiness without exposing secrets |
| GET | `/v1/metrics` | Paid-gateway operational counters |
| GET | `/v1/proof` | Discover XGuard ProofRail |
| POST | `/v1/proofs/verify` | Verify a ProofRail compact proof |
| GET | `/v1/capabilities/{id}` | — |
| GET | `/v1/results/{payment_identifier}` | — |
| GET | `/agent-card.json` | Canonical discovery alias |
| GET | `/openapi.yaml` | Canonical discovery alias |
| GET | `/pricing` | Canonical discovery alias |
| GET | `/.well-known/agent-directory.json` | Discover the canonical XGuard agent card and tool catalog |
| GET | `/.well-known/oauth-protected-resource` | Resource metadata; public x402 tools do not require OAuth |
| GET | `/.well-known/oauth-protected-resource/mcp` | Resource metadata; public x402 tools do not require OAuth |

## Machine-readable artifacts (6)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/xguardgate-com/refs/heads/main/openapi/xguardgate-com-openapi.json
- **OpenAPI** — https://api.xguardgate.com/openapi.json
- **Documentation** — https://xguardgate.com/developers
- **APIReference** — https://api.xguardgate.com/openapi.json
- **Overlay** — https://raw.githubusercontent.com/api-evangelist/xguardgate-com/refs/heads/main/overlays/xguardgate-com-openapi-overlay.yaml
- **APIsJSON** — https://raw.githubusercontent.com/api-evangelist/xguardgate-com/refs/heads/main/apis.yml

## Other XGuard APIs (3)

- [XGuard MCP Server](https://apis.io/apis/xguardgate-com/xguard-mcp-server/)
- [XGuard A2A Agent](https://apis.io/apis/xguardgate-com/xguard-a2a-agent/)
- [XGuard Reconcile API](https://apis.io/apis/xguardgate-com/xguard-reconcile-api/)

## Tags

Agents, x402, Web Extraction, Feed Aggregation, Credential Broker, Micropayments

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/xguardgate-com/xguard-universal-paid-agent-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/xguardgate-com/.
