agent402.dev · Authentication Profile

Agent402 Dev Authentication

Authentication

agent402.dev declares 1 security scheme(s) across its OpenAPI definitions.

Companyx402Agentic PaymentsAgentic CommerceAI AgentsA2ATechnical SEOWebsite AuditsURL EvidenceDeveloper ToolsBase
Methods: Schemes: 1 OAuth flows: API key in:

Security Schemes

x402 payment
scheme: exact

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: >-
  openapi/agent402-dev-openapi.yml (x-payment-client-guidance, x-payment-info, 402 response descriptions,
  info.x-guidance), https://agent402.dev/api/product (paymentClient, purchaseOptions, purchaseSafety),
  https://agent402.dev/.well-known/x402 (accepts[]), the homepage "Agent Payment" / "402 Retry Flow" sections
  and the /site-release-audit buyer-setup page, and live 402 challenges observed 2026-09-20 UTC.
docs: https://agent402.dev/site-release-audit
checked: '2026-09-19'
summary: >-
  There is no authentication in the credential sense — no accounts, no sign-up, no API keys, no OAuth, no
  sessions. Access to every paid resource is PAYMENT-AS-AUTHORIZATION under x402 v2: the first request gets
  HTTP 402 with a PAYMENT-REQUIRED header naming the exact USDC amount on Base (eip155:8453) and the payee;
  the client signs that authorization and repeats the identical request with a PAYMENT-SIGNATURE header;
  the server verifies, delivers, and settles. Four support routes are free and anonymous. The OpenAPI
  declares NO securitySchemes, so derive-authentication.py wrote nothing; this file is the searched
  profile and overlays/ adds the scheme the contract omits.
model: payment-as-authorization (x402 v2, exact scheme, USDC on Base)
accounts: none — 'no account' (homepage and product page); 'buyer wallet required'
api_keys: none
oauth2: none
schemes:
  - name: x402
    type: payment
    protocol: x402
    protocol_version: 2
    scheme: exact
    network: eip155:8453
    asset: {symbol: USDC, contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913', decimals: 6}
    pay_to: '0xb0BbF890375B2ea1C2812887aE0331DD82eee92c'
    request_header: PAYMENT-SIGNATURE
    response_headers: [PAYMENT-REQUIRED, PAYMENT-RESPONSE]
    challenge_status: 402
    max_timeout_seconds: 300
    eip712_domain: {name: USD Coin, version: '2'}   # accepts[].extra in the live challenge — the EIP-3009 transferWithAuthorization domain
    applies_to: ["taskDayPlan", "websitePreflight", "verifiedUrlEvidence", "siteReleaseAudit", "auditX402", "x402Health", "downloadWayfarersDeck", "downloadQrCampaignPack"]
    free_routes: ["siteReleaseAuditEligibility", "siteReleaseAuditSample", "siteReleaseAuditMethodology", "siteReleaseAuditCaseStudy"]
    also_free: [/health, /metrics, /pmf/scorecard, /meta.json, /api/product, /openapi.json, /.well-known/x402, /llms.txt]
    client_requirement_verbatim: 'Use an x402-capable buyer client that validates the pinned terms and supplies PAYMENT-SIGNATURE. Plain curl is a 402 probe only and never pays.'
    docs: https://agent402.dev/site-release-audit
buyer_paths_published:
  - {path: browser-wallet, detail: 'injected MetaMask or Coinbase Wallet on Base with >= 5 USDC; the page "never receives or stores your private key"; one signed attempt, no automatic retry', url: https://agent402.dev/site-release-audit}
  - {path: x402-client, detail: 'any x402 v2 client that binds PAYMENT-SIGNATURE to this resource and preserves the eligibility-checked body', url: https://agent402.dev/site-release-audit}
  - {path: node-recipe, detail: 'npm install --save-exact @payanagent/sdk@0.2.2 @x402/fetch@2.18.0 @x402/evm@2.18.0 viem@2.55.1; WALLET_KEY env var; run once', url: https://agent402.dev/site-release-audit}
  - {path: payan-marketplace, detail: 'agents-only alternate route, offer kh70zbzh8m5awkegpvn7tc82798aed20 (priceCents 500) at https://payanagent.com/x402/<offerId>; the provider warns Payan "challenges before seller input validation"', url: https://agent402.dev/api/product}
identity_and_delegation:
  agent_identity: none — no Web Bot Auth, no HTTP Message Signatures, no ERC-8004 reference; the paying wallet is the only identity
  delegated_identity: none
  dynamic_client_registration: not applicable (no clients to register)
  rfc9728_protected_resource_metadata: absent (404)
spec_gaps:
  - 'components.securitySchemes is absent and no operation carries security[], so a generated client sees an open API; the x-payment-client-guidance extension on siteReleaseAudit and x-payment-info on the eight paid operations are where the contract actually states the requirement.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agent402-dev-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.