gpt55-token-gateway · Authentication Profile
558686 Xyz Authentication
Authentication
gpt55-token-gateway secures its APIs with x402-payment, http-bearer, and api-key-header across 4 declared security schemes, as derived from its OpenAPI definitions.
x402Agentic PaymentsMCPA2AAI GatewayOpenAI-CompatibleLLMAI AgentsUSDCBaseAPI RelayDeveloper Tools
Methods: x402-payment, http-bearer, api-key-header
Schemes: 4
OAuth flows:
API key in:
Security Schemes
x402Payment x402
· in: header ()
operatorBearer http
scheme: bearer
none none
bearerAuth http
scheme: bearer
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: >-
Derived baseline from openapi/558686-xyz-sub2api-openapi.json (the only spec with a
securityScheme) by derive-authentication.py, then upgraded from the provider docs:
https://gpt55.558686.xyz/buyer-guide ("No account, subscription, or public API key is required
for public paid calls"; "Integration flow"), /llms-full.txt ("A private Bearer token is also
accepted for owner/admin testing"), /mcp/config (authentication block), /.well-known/x402
(payment, settlement, privateKeySentToService), SECURITY.md ("The service never needs a buyer's
private key"), the live 402 and 401 responses observed 2026-09-20, and the Sub2API docs
https://sub2api.558686.xyz/docs/getting-started.html and /docs/register-guide.html.
docs:
- https://gpt55.558686.xyz/buyer-guide
- https://gpt55.558686.xyz/x402/guides/ai-agent-x402-api
- https://sub2api.558686.xyz/docs/getting-started.html
checked: '2026-09-19'
summary:
types: [x402-payment, http-bearer, api-key-header]
note: >-
Two different models on two hosts. GPT55 has NO identity credential for the public: every
paid route is gated by an x402 payment presented in the X-PAYMENT header after a 402 quote,
and the discovery/metadata surface (GET /v1/models, MCP initialize/tools/list/resources/list,
every JSON manifest, the /api-market utilities) is fully anonymous. A private Bearer token
exists but is documented as an operator-only bypass, not a public option. Sub2API is a
conventional API-key relay: Authorization: Bearer <key> (also x-api-key or a query key),
with keys created in a console whose self-service registration is currently closed.
no_oauth: 'No OAuth 2.0, OIDC, scopes, RFC 8414 or RFC 9728 metadata anywhere; scopes/ is therefore not emitted.'
schemes:
- name: x402Payment
api: GPT55 Model Gateway API (gpt55.558686.xyz)
type: x402
version: '2'
in: header
header: X-PAYMENT
declared_in_spec: false
declared_in_spec_note: 'The GPT55 OpenAPI declares no securitySchemes; the 402 response on 36 of 37 operations and x-x402-price are the only in-contract signals. overlays/558686-xyz-gpt55-model-gateway-overlay.yaml adds an apiKey-in-header scheme named x402Payment as the closest OpenAPI expression.'
flow_verbatim:
- 'Send the intended HTTP request without a payment header.'
- 'Read the HTTP 402 response and its accepts array.'
- 'Select the exact accept requirement and generate the x402 payment header with your Base USDC wallet.'
- 'Retry the same request with the payment header.'
- 'Read the payment response header and JSON body. Successful paid model calls return OpenAI-compatible JSON.'
requirement_observed: {scheme: exact, network: 'eip155:8453', asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 (USDC)', payTo: '0x1f0130669ca6fd02e025a984cc038f139df19a2f', maxTimeoutSeconds: 300, facilitator: 'provider-pool (xpay active)'}
response_headers: [PAYMENT-REQUIRED, X-PAYMENT-REQUIRED, PAYMENT-RESPONSE, X-PAYMENT-RESPONSE, x-x402-receipt-id, x-x402-receipt-url]
account_required: false
api_key_required: false
kyc_required: false
private_key_sent_to_service: false
client_libraries_named: ['@x402/fetch + @x402/evm + viem (buyer guide quickstart)', 'first-payment-client.mjs (provider script, quote-only by default; PAY_REAL_X402=1 + EVM_PRIVATE_KEY in the buyer process to pay)']
applies_to: all 36 paid operations; GET /v1/models is anonymous
- name: operatorBearer
api: GPT55 Model Gateway API (gpt55.558686.xyz)
type: http
scheme: bearer
declared_in_spec: false
public: false
verbatim: 'A private Bearer token is also accepted for owner/admin testing.'
verbatim_2: 'Private Bearer keys are only an operator bypass; public buyers should use the x402 quote and payment flow.'
note: 'Recorded because the provider documents it; there is no way for a member of the public to obtain one. An unpaid request with an invalid X-PAYMENT header returned the ordinary 402 quote, not a 401.'
- name: none
api: 'GPT55 discovery surface + GPT-5.5 Utility Tools for API.market (gpt55.558686.xyz/api-market)'
type: none
declared_in_spec: 'api-market OpenAPI declares no securitySchemes; its description says commercial access is configured in API.market'
observed: 'GET /api-market/v1/tools/timestamp and /text-stats answered 200 with no credential and no payment (2026-09-20); GET /v1/models, MCP initialize/tools/list/resources/list and every manifest likewise anonymous.'
- name: bearerAuth
api: Sub2API OpenAI-compatible API (sub2api.558686.xyz, api.558686.xyz)
type: http
scheme: bearer
bearerFormat: API key
declared_in_spec: true
sources: [openapi/558686-xyz-sub2api-openapi.json]
alternate_carriers: ['x-api-key header', 'query key (named in the 401 message, truncated in the observed body)']
errors: {missing: '401 {"code":"API_KEY_REQUIRED","message":"API key is required in Authorization header (Bearer scheme), x-api-key header, or ..."}', invalid: '401 {"code":"INVALID_API_KEY","message":"Invalid API key"}'}
key_issuance: 'Console https://sub2api.558686.xyz/keys after email registration + verification; docs: "创建成功后立即保存完整 Key,它通常只会完整显示一次" (the full key is normally shown only once). Registration is CLOSED per /verify-models (registration_enabled=false, google_oauth_enabled=false); "contact the administrator for a test key".'
base_url_for_clients: https://sub2api.558686.xyz/v1
applies_to: all three operations (GET /v1/models, POST /v1/chat/completions, POST /v1/responses)
mcp:
endpoint: https://gpt55.558686.xyz/mcp
auth: none for initialize / tools/list / resources/list; tool results are HTTP routes that require the x402 payment above
declared: '/mcp/config authentication {type: x402-payment-header, apiKeyRequired: false, accountRequired: false, kycRequired: false, quoteFirst: true}'
a2a:
endpoint: https://gpt55.558686.xyz/a2a
auth: 'agent card authentication: [{schemes: [x402]}]; payment.accepts[] carries the requirement'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/558686-xyz-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.