agent402.dev · Authentication Profile
Agent402 Dev Authentication
Authentication
agent402.dev declares 1 security scheme(s) across its OpenAPI definitions.
Companyx402Agentic PaymentsAgentic CommerceAI AgentsA2ATechnical SEOWebsite AuditsURL EvidenceDeveloper ToolsBase
Methods:
Schemes: 1
OAuth flows:
API key in:
Security Schemes
x402 payment
scheme: exact
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: >-
openapi/agent402-dev-openapi.yml (x-payment-client-guidance, x-payment-info, 402 response descriptions,
info.x-guidance), https://agent402.dev/api/product (paymentClient, purchaseOptions, purchaseSafety),
https://agent402.dev/.well-known/x402 (accepts[]), the homepage "Agent Payment" / "402 Retry Flow" sections
and the /site-release-audit buyer-setup page, and live 402 challenges observed 2026-09-20 UTC.
docs: https://agent402.dev/site-release-audit
checked: '2026-09-19'
summary: >-
There is no authentication in the credential sense — no accounts, no sign-up, no API keys, no OAuth, no
sessions. Access to every paid resource is PAYMENT-AS-AUTHORIZATION under x402 v2: the first request gets
HTTP 402 with a PAYMENT-REQUIRED header naming the exact USDC amount on Base (eip155:8453) and the payee;
the client signs that authorization and repeats the identical request with a PAYMENT-SIGNATURE header;
the server verifies, delivers, and settles. Four support routes are free and anonymous. The OpenAPI
declares NO securitySchemes, so derive-authentication.py wrote nothing; this file is the searched
profile and overlays/ adds the scheme the contract omits.
model: payment-as-authorization (x402 v2, exact scheme, USDC on Base)
accounts: none — 'no account' (homepage and product page); 'buyer wallet required'
api_keys: none
oauth2: none
schemes:
- name: x402
type: payment
protocol: x402
protocol_version: 2
scheme: exact
network: eip155:8453
asset: {symbol: USDC, contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913', decimals: 6}
pay_to: '0xb0BbF890375B2ea1C2812887aE0331DD82eee92c'
request_header: PAYMENT-SIGNATURE
response_headers: [PAYMENT-REQUIRED, PAYMENT-RESPONSE]
challenge_status: 402
max_timeout_seconds: 300
eip712_domain: {name: USD Coin, version: '2'} # accepts[].extra in the live challenge — the EIP-3009 transferWithAuthorization domain
applies_to: ["taskDayPlan", "websitePreflight", "verifiedUrlEvidence", "siteReleaseAudit", "auditX402", "x402Health", "downloadWayfarersDeck", "downloadQrCampaignPack"]
free_routes: ["siteReleaseAuditEligibility", "siteReleaseAuditSample", "siteReleaseAuditMethodology", "siteReleaseAuditCaseStudy"]
also_free: [/health, /metrics, /pmf/scorecard, /meta.json, /api/product, /openapi.json, /.well-known/x402, /llms.txt]
client_requirement_verbatim: 'Use an x402-capable buyer client that validates the pinned terms and supplies PAYMENT-SIGNATURE. Plain curl is a 402 probe only and never pays.'
docs: https://agent402.dev/site-release-audit
buyer_paths_published:
- {path: browser-wallet, detail: 'injected MetaMask or Coinbase Wallet on Base with >= 5 USDC; the page "never receives or stores your private key"; one signed attempt, no automatic retry', url: https://agent402.dev/site-release-audit}
- {path: x402-client, detail: 'any x402 v2 client that binds PAYMENT-SIGNATURE to this resource and preserves the eligibility-checked body', url: https://agent402.dev/site-release-audit}
- {path: node-recipe, detail: 'npm install --save-exact @payanagent/sdk@0.2.2 @x402/fetch@2.18.0 @x402/evm@2.18.0 viem@2.55.1; WALLET_KEY env var; run once', url: https://agent402.dev/site-release-audit}
- {path: payan-marketplace, detail: 'agents-only alternate route, offer kh70zbzh8m5awkegpvn7tc82798aed20 (priceCents 500) at https://payanagent.com/x402/<offerId>; the provider warns Payan "challenges before seller input validation"', url: https://agent402.dev/api/product}
identity_and_delegation:
agent_identity: none — no Web Bot Auth, no HTTP Message Signatures, no ERC-8004 reference; the paying wallet is the only identity
delegated_identity: none
dynamic_client_registration: not applicable (no clients to register)
rfc9728_protected_resource_metadata: absent (404)
spec_gaps:
- 'components.securitySchemes is absent and no operation carries security[], so a generated client sees an open API; the x-payment-client-guidance extension on siteReleaseAudit and x-payment-info on the eight paid operations are where the contract actually states the requirement.'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agent402-dev-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.