AgentCheck · Authentication Profile

Agentcheck Care Authentication

Authentication

AgentCheck secures its APIs with apiKey, token-in-path, and token-in-query across 5 declared security schemes, as derived from its OpenAPI definitions.

AI AgentsAI SafetySecurity TestingPrompt InjectionLLM EvaluationA2AAgent-NativeChatbotsComplianceDeveloper Tools
Methods: apiKey, token-in-path, token-in-query Schemes: 5 OAuth flows: API key in:

Security Schemes

X-API-Key apiKey
· in: header ()
ADMIN_STATS_TOKEN apiKey
· in: unknown ()
exam-session-token token-in-path
· in: path (token)
report-magic-link token-in-query
· in: query ()
stripe-webhook inbound-webhook

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: probed
source: live anonymous probes of https://agentcheck.care on 2026-09-19, read against openapi/_original/agentcheck-care-openapi.json
docs: https://agentcheck.care/docs
spec: openapi/agentcheck-care-openapi.yml
summary:
  types:
  - apiKey
  - token-in-path
  - token-in-query
  transport: HTTPS only; Cloudflare in front of a FastAPI origin
  note: >-
    The served OpenAPI declares NO securitySchemes and NO security requirements on any of its 35
    operations, so derive-authentication.py produced nothing. The authentication model below is what the
    live API told an anonymous caller plus what the operation descriptions say. Most of the surface —
    tiers, free-scan pool, public stats, validate-bot, start-checkup (free), create-checkout, the A2A
    endpoint and the agent card — is deliberately anonymous: the product has no login and no account.
    Three credential-shaped mechanisms exist and none is documented on a page a developer can find.
schemes:
- name: X-API-Key
  type: apiKey
  in: header
  header: X-API-Key
  applies_to:
  - GET /api/credits/balance (credit_balance_api_credits_balance_get)
  evidence: >-
    Anonymous GET https://agentcheck.care/api/credits/balance returned HTTP 401, application/json,
    {"detail":"Missing X-API-Key header"} on 2026-09-19.
  issuance: undocumented — no page describes how to obtain an API key or what credits are
  sources:
  - https://agentcheck.care/api/credits/balance
- name: ADMIN_STATS_TOKEN
  type: apiKey
  in: unknown
  applies_to:
  - GET /api/stats/internal (get_internal_stats_api_stats_internal_get)
  evidence: >-
    The operation description says "Requires ADMIN_STATS_TOKEN"; anonymous GET returned HTTP 401
    {"error":"Unauthorized"} (a different envelope from the X-API-Key 401). Operator-only; not a
    developer credential.
  sources:
  - openapi/_original/agentcheck-care-openapi.json
- name: exam-session-token
  type: token-in-path
  in: path
  parameter: token
  applies_to:
  - GET /exam/{token}
  - GET /exam/{token}/status
  - POST /exam/{token}/relaunch
  - POST /exam/{token}/v1/chat/completions
  evidence: >-
    The "exam" mode generates a per-checkup secure URL that the customer pastes into their bot as an
    OpenAI-compatible endpoint (home page step 1; the chat_completions operation description). The
    token in the path IS the credential. Anonymous GET /exam/nonexistent/status returned 404
    {"detail":"Exam session not found"}.
  sources:
  - https://agentcheck.care/
  - openapi/_original/agentcheck-care-openapi.json
- name: report-magic-link
  type: token-in-query
  in: query
  parameters:
  - token
  - code
  applies_to:
  - GET /report/{checkup_id} (magic_link_report_report__checkup_id__get)
  evidence: >-
    "Serve a persisted report via magic link token + optional access code." The privacy policy (3.1)
    says reports are reachable only via a unique magic link carrying a cryptographic token and tells
    users to treat the link like a password. Anonymous GET /report/nonexistent returned 404
    {"detail":"Report not found"}.
  sources:
  - https://agentcheck.care/privacy
  - openapi/_original/agentcheck-care-openapi.json
- name: stripe-webhook
  type: inbound-webhook
  applies_to:
  - POST /api/stripe-webhook (stripe_webhook_api_stripe_webhook_post)
  note: >-
    Receiver for Stripe payment events. Signature verification is not described anywhere public and is
    not asserted here; the endpoint is Stripe-facing, not developer-facing.
anonymous_surface:
  operations:
  - get_tiers_api_tiers_get
  - free_scans_endpoint_api_free_scans_get
  - free_scan_status_api_free_scan_status_get
  - get_public_stats_api_stats_public_get
  - health_api_health_get
  - validate_bot_api_validate_bot_post
  - start_checkup_api_checkup_post
  - create_checkout_api_checkout_post
  - upgrade_checkout_api_checkout_get
  - a2a_endpoint_a2a_post
  - agent_card__well_known_agent_card_json_get
  note: Every one of these answered an anonymous request without a challenge (200, 302 or a 404 on an unknown id). The A2A card declares no securitySchemes, consistent with the open endpoint.
customer_credentials_in_requests:
  note: >-
    CheckupRequest and CheckoutRequest carry an optional `api_key` field — the CUSTOMER's key for their
    own bot's chat API, which AgentCheck uses to call the bot under test. The privacy policy (1.3) states
    it is held in memory for the session only and never written to disk. This is a credential the caller
    sends, not one AgentCheck issues.
gaps:
- No securitySchemes in the OpenAPI; a generated client will treat /api/credits/balance as anonymous and get a 401.
- No developer page documents the X-API-Key credential or how to obtain one.
- No OAuth, no OIDC, no RFC 9728 protected-resource metadata (all /.well-known OAuth paths 404).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agentcheck-care-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.