Aelf · Authentication Profile

Aelf Inc Authentication

Authentication

Aelf declares 0 security scheme(s) across its OpenAPI definitions.

CompanyBlockchainLayer 1Web3Smart ContractsCross-ChainDeveloper ToolsProtobufAgent SkillsCryptocurrency
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-09-09'
method: searched
source: >-
  https://docs.aelf.com/tools/web-api/net-api/ (Basic authentication on the peer operations),
  https://github.com/AElfProject/aelf-agent-gateway#readme (bearer + NyxID delegation JWT),
  https://raw.githubusercontent.com/AElfProject/AElf/dev/src/AElf.WebApp.Application.Chain/Error.cs
  and the two contracts in openapi/
summary: >-
  The aelf node Web API is an unauthenticated API. There is no key, no token and no OAuth: reads
  are open and even the transaction-submitting writes take no HTTP credential, because authority
  travels inside the signed transaction rather than in a header. Two exceptions and one caveat:
  the peer add/remove operations are documented as HTTP Basic, the self-hosted agent gateway uses
  bearer plus a delegated JWT, and NEITHER of the node's auth requirements is declared in its
  OpenAPI.
surfaces:
- surface: aelf Node Web API
  spec: openapi/aelf-inc-node-web-api-openapi.json
  declared_security_schemes: []
  effective_model: none (anonymous) for all /api/blockChain operations
  authority_model: >-
    Write authority is cryptographic, not HTTP. A transaction carries From, To, MethodName, Params,
    RefBlockNumber/RefBlockPrefix and a Signature produced by the sender's private key; the node
    validates the signature (error 20013 InvalidSignature) and the chain enforces permissions.
    Sending a transaction is therefore an open endpoint that only accepts already-authorized bytes.
  key_management: >-
    Keys live client-side — created by `aelf-command create`, loaded from private key or mnemonic,
    or held by a wallet (NightElf, Portkey). The API never sees them.
  exceptions:
  - operations:
    - POST /api/net/peer
    - DELETE /api/net/peer
    scheme: http basic
    documented_at: https://docs.aelf.com/tools/web-api/net-api/
    source_signal: >-
      Error.cs carries the constant NeedBasicAuth = "User name and password for basic auth should
      be set", confirming the node enforces it when configured.
    gap: >-
      The served OpenAPI declares NO securitySchemes at all, so these two operations look
      anonymous to any machine reading the contract. A generated client will fail on them.
- surface: aelf Agent Gateway
  spec: openapi/aelf-inc-agent-gateway-openapi.yaml
  declared_security_schemes:
  - name: GatewayBearerAuth
    type: http
    scheme: bearer
  effective_model: bearer token, plus NyxID identity and delegation JWTs in production
  details:
    open_operations:
    - GET /health
    - /openapi.json
    - /docs
    production_verification: signature, issuer, audience, scope and expiry
    configuration:
    - NYXID_JWKS_URL
    - NYXID_ISSUER
    - NYXID_AUDIENCE
    - NYXID_REQUIRED_DELEGATION_SCOPE
    admin_model: >-
      Admin access derives only from a verified `sub` present in GATEWAY_ADMIN_NYX_USER_IDS;
      role/scope headers cannot grant it. `trusted_headers` identity is restricted to
      non-production loopback development.
    scopes_note: >-
      A dedicated `wallet:write` delegation scope is named in the provider's own release notes as a
      remaining blocker rather than a shipped feature, so no scope reference page exists and no
      scopes/ artifact is emitted.
- surface: MCP (aelf-node-skill)
  transport: stdio
  effective_model: none for reads; AELF_PRIVATE_KEY environment variable for writes
  detail: mcp/aelf-inc-mcp.yml
oauth2: false
oidc: false
mtls: false
api_keys: false
discovery_documents:
  openid_configuration: absent
  oauth_authorization_server: absent
  probed: well-known/aelf-inc-well-known.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aelf-inc-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.