Agent Ready · Authentication Profile

Agent Ready Dev Authentication

Authentication

Agent Ready secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.

AgentsAgent ReadinessWebsite ScanningDeveloper ToolsMCPA2Allms-txtx402NLWebAccessibilityAgent-NativeAustralia
Methods: http Schemes: 1 OAuth flows: API key in: header

Security Schemes

ApiKey http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/agent-ready-dev-openapi.yml
docs: https://agent-ready.dev/auth
additional_docs:
- https://agent-ready.dev/docs/api#authentication
- https://agent-ready.dev/.well-known/oauth-protected-resource
- https://agent-ready.dev/.well-known/oauth-authorization-server
summary:
  types:
  - http
  http_schemes: [bearer]
  api_key_in: [header]
  oauth2_flows: []
  credential_types: [ar_live_ Pro API key]
  public_operations: [askGet, askPost, scanMcp, x402ScanChallenge, x402Scan]
  discovery: RFC 9728 protected-resource metadata + RFC 8414 authorization-server metadata + WWW-Authenticate on 401
  dynamic_client_registration: false
  delegated_identity: false
schemes:
- name: ApiKey
  type: http
  scheme: bearer
  bearerFormat: ar_live_<prefix>_<secret>
  description: API key issued from /dashboard/api-keys. Pro subscription required.
  sources:
  - openapi/agent-ready-dev-openapi.yml
  applies_to: [startScan, listScans, getScan]
  header: 'Authorization: Bearer ar_live_<prefix>_<secret>'
  key_format: >-
    ar_live_<prefix>_<secret> — the prefix is non-secret and identifies the key in the dashboard; only the
    SHA-256 hash of the secret is stored server-side, so a leaked key must be rotated, not recovered.
  issuance: https://agent-ready.dev/dashboard/api-keys (human-mediated; shown once; Pro plan required)
  rotation: Two keys can be active simultaneously for zero-downtime rotation; revoke from the dashboard, instant and irreversible.
  shared_surfaces: The same key authenticates REST (/api/v1/scans), the hosted MCP endpoint (/api/v1/mcp) and the A2A endpoint (/api/v1/a2a), and they share one rate-limit budget.
  ci_convention: GitHub Actions secret AGENT_READY_API_KEY; CLI/SDK env var AGENT_READY_API_KEY.
agent_auth:
  model: machine-to-machine Bearer key (client-credentials-shaped, but issued out of band from a dashboard rather than at a token endpoint)
  protected_resource_metadata:
    url: https://agent-ready.dev/.well-known/oauth-protected-resource
    file: well-known/agent-ready-dev-oauth-protected-resource.json
    resource: https://agent-ready.dev/api/v1/mcp
    authorization_servers: [https://agent-ready.dev]
    scopes_supported: [scan:read, scan:write, ask:read, mcp]
  authorization_server_metadata:
    url: https://agent-ready.dev/.well-known/oauth-authorization-server
    file: well-known/agent-ready-dev-oauth-authorization-server.json
    issuer: https://agent-ready.dev
    grant_types_supported: [urn:ietf:params:oauth:grant-type:api-key]
    registration_endpoint: https://agent-ready.dev/dashboard/api-keys (human dashboard — not RFC 7591)
    agent_auth_block: 'register_uri, identity_types_supported [anonymous, identity_assertion], skill https://agent-ready.dev/auth.md'
  www_authenticate: 'Bearer realm="agent-ready", error="invalid_token", resource_metadata="https://agent-ready.dev/.well-known/oauth-protected-resource"'
  observed: 'GET https://agent-ready.dev/api -> 401 with the WWW-Authenticate challenge above (2026-09-19).'
  not_supported:
  - OAuth 2.1 authorization-code flow
  - RFC 7591 dynamic client registration
  - RFC 7521 identity_assertion / id-jag token exchange
  - RFC 7009 revocation endpoint (dashboard revocation only)
  - OpenID Connect discovery
  bot_identity:
    web_bot_auth: true
    directory: https://agent-ready.dev/.well-known/http-message-signatures-directory
    note: The provider publishes its own RFC 9421 Ed25519 key directory for the agent-ready-scanner bot; it identifies the bot, the Bearer key authorises the call.
alternatives_without_a_key:
  anonymous_free_tier: POST https://agent-ready.dev/api/scan — 3 scans / 30 days per IP at 25-page depth; also what the stdio MCP package and CLI use keyless.
  mcp_apps_endpoint: https://agent-ready.dev/api/apps/mcp — tools/call with no credential; rate-limited per opaque ChatGPT user id.
  x402_mpp: 'Pay per scan with an X-PAYMENT header or MPP Authorization: Payment on /api/x402/scan — $0.02 / $0.25 USDC on Base, no account.'
  public_endpoints: [GET/POST /api/v1/ask, POST /api/v1/scan/mcp]
errors:
  401: {code: invalid_token, meaning: Missing, malformed, expired or revoked Bearer token}
  403: {code: insufficient_scope, meaning: Token valid but the plan tier lacks access (e.g. Free-tier key calling /api/v1/scans); OpenAPI Error example code subscription_required}
  429: {meaning: 'Over 10/min or 200/day; Retry-After present'}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agent-ready-dev-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.