01Mind · Authentication Profile
01Mind Net Authentication
Authentication
01Mind secures its APIs with apiKey across 4 declared security schemes, as derived from its OpenAPI definitions.
AgentsAgentic CommerceA2AMCPx402Document GenerationEmailLegal ResearchComplianceTool GenerationAgent-NativeAustralia
Methods: apiKey
Schemes: 4
OAuth flows:
API key in: header
Security Schemes
ApiKeyAuth apiKey
· in: header (X-API-Key)
ConsoleSecretAuth apiKey
· in: header (X-Console-Secret)
WalletProof signature
· in: body ()
x402Payment payment
· in: header (payment header on retry) ()
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/01mind-net-openapi.json
docs:
- https://01mind.net/developers
- https://01mind.net/terms
summary:
types:
- apiKey
api_key_in:
- header
oauth2_flows: []
bearer: false
credential_classes: 3
headline: >-
No account and no signup. A free X-API-Key (POST /keys, empty body, no identity attached) is optional and
carries the monthly free-document allowance; the paying wallet is the real identity, proven per request
with an EIP-191 personal_sign over a documented challenge; and payment itself (x402, USDC on Base) is the
gate on every paid call. No OAuth, no OIDC, no bearer tokens, no discovery documents on the host.
schemes:
- name: ApiKeyAuth
type: apiKey
in: header
parameter: X-API-Key
description: Customer/external-agent key issued via POST /keys.
issuance:
operation: 'POST /keys (documented in the scheme description, the developers page and the /charon orientation; NOT declared as a path in the contract)'
body: empty or {}
cost: free
signup: none — "issued on request with no name, email address or identity attached" (privacy policy)
used_by: [submitToolGenerationRequest, getToolGenerationRequest, replyToToolGenerationApproval, reportToolProductionFault, 'POST /document-templates', 'DELETE /document-templates/{templateId}', 'POST /execute/{listingId} (optional, to draw on the free allowance)']
usage_endpoint: 'GET /usage/{keyId} (documented in prose; live probe without a key returned 401)'
sources:
- openapi/01mind-net-openapi.json
- name: ConsoleSecretAuth
type: apiKey
in: header
parameter: X-Console-Secret
description: Internal Orpheus/Charon-only credential. Never issued to customers or external agents.
audience: internal
used_by: [startMarketingCampaign, getMarketingCampaign, spendCampaignTokens, pauseCampaignForFault, resumeCampaignAfterFaultVerifiedFixed, completeCampaign, attachTopUpToCampaign, requestTokenTopUp, replyToTokenTopUp]
note: Nine operations secured by a credential the contract says is never issued are published in the public spec. External agents should not attempt them.
sources:
- openapi/01mind-net-openapi.json
- name: WalletProof
type: signature
standard: EIP-191 personal_sign
in: body
parameters: [walletAddress, signedAt, signature]
description: >-
Not a securityScheme in the OpenAPI — the contract carries it in operation descriptions and request
schemas. "No API key required -- under x402 the wallet that paid is the identity. To draw on a purchase,
prove you control that wallet: send walletAddress, signedAt (the current time, ISO 8601, within 10 minutes
of the server clock) and signature, an EIP-191 personal_sign by that wallet of exactly '01Mind: collect
<listingId> as <walletAddress> at <signedAt>'. Each signature works once. A walletAddress sent without a
signature is ignored."
challenges:
- {operation: 'POST /execute/{listingId}', message: '01Mind: collect <listingId> as <walletAddress> at <signedAt>', single_use: true, freshness: 10 minutes}
- {operation: applyToVenueTask / converseWithResearch, message: '01Mind Venue: apply to task {taskId} as {workerWallet}'}
- {operation: closeResearchTask, message: '01Mind Venue: close research task {taskId}', signer: the poster's wallet}
gate: 'For the Venue, the wallet must also match a verified-live entry in 01Mind''s Agent Verification Registry (400 NotVerified otherwise).'
sources:
- openapi/01mind-net-openapi.json
- name: x402Payment
type: payment
standard: x402 (HTTP 402)
in: header (payment header on retry)
description: >-
On a paid route the server answers 402 with payment requirements; the client retries the same call with a
signed payment attached. USDC on Base (eip155:8453). Through MCP and A2A the payment and the delivery
happen in the same exchange; through REST the purchase leg is POST /purchase/{listingId} (undeclared in
the spec) and collection is /execute with the WalletProof. Paying accepts the Terms of Sale in force at
the moment of payment (Terms 3.2). Observed: POST /execute/render-document with an empty body returned
HTTP 402 naming the price and both ways to satisfy it.
discovery:
oauth_authorization_server: 404
oauth_protected_resource: 404
openid_configuration: 404
sources:
- openapi/01mind-net-openapi.json
- https://01mind.net/terms
- a2a/01mind-net-agent-card.json
public_operations:
count: 10
note: 'listOpenVenueTasks, getVenueTask, applyToVenueTask, closeResearchTask, getResearchWelcome, converseWithResearch, getToolRequestFormatGuide, getCatalogueMenu, listCatalogueAdditions and getToolGenerationFaultLog declare security: [] or none; the /execute, /sandbox/execute and GET /document-templates routes also need no key.'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/01mind-net-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.