Agent Exchange · Authentication Profile

Agentexchange Work Authentication

Authentication

Agent Exchange secures its APIs with x402-payment and apiKey across 4 declared security schemes, as derived from its OpenAPI definitions.

AgentsAgentic Commercex402MCPA2AAI VisibilityGenerative Engine OptimizationCryptoBlockchainOn-Chain DataWeb SearchPrediction MarketsDeFiMacroeconomicsPublic ProcurementMarketplaceAgent-Native
Methods: x402-payment, apiKey Schemes: 4 OAuth flows: API key in: header

Security Schemes

x402 payment (primary) x402-payment
· in: header (X-PAYMENT (x402 v1) | PAYMENT-SIGNATURE (x402 v2))
Card-bought API key (optional) apiKey
· in: header (Authorization: Bearer ak_… or X-API-Key)
Agent Planets api_key apiKey
· in: body (api_key)
none (free surfaces) none

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://store.agentexchange.work/api-docs
derived_from: openapi/agentexchange-work-api-store-openapi.json
docs:
- https://store.agentexchange.work/llms.txt
- https://store.agentexchange.work/.well-known/x402
- https://store.agentexchange.work/.well-known/oauth-protected-resource
- https://store.agentexchange.work/billing/catalog.json
- https://store.agentexchange.work/.well-known/mcp.json
- https://agentexchange.work/oracle/info
- https://planets.agentexchange.work/llms.txt
summary:
  types:
  - x402-payment
  - apiKey
  api_key_in:
  - header
  oauth2: false
  oidc: false
  model: >-
    None of the three OpenAPI documents declares a securitySchemes block or a security requirement
    (derive-authentication.py therefore produced nothing), so this profile is read from the provider's own
    documents. The primary model is payment in place of authentication: no account, no key, no OAuth — an
    unpaid call to a paid route returns HTTP 402 with x402 requirements and the caller retries with a signed
    USDC authorization in X-PAYMENT (v1) or PAYMENT-SIGNATURE (v2). A second, optional model is a card-bought
    API key that unlocks the same routes over plain HTTPS. The MCP host states explicitly that it uses no OAuth
    (a JSON 404 at /.well-known/oauth-protected-resource), and no OpenID/OAuth discovery document exists on any
    host. Agent Planets issues a free per-planet api_key on claim for its own mutating calls.
schemes:
- name: x402 payment (primary)
  type: x402-payment
  in: header
  parameter: X-PAYMENT (x402 v1) | PAYMENT-SIGNATURE (x402 v2)
  applied_to: 'the 85 paid store routes (x-payment-info on each), the planets /survey, /odds and /api/accept, and the oracle /oracle'
  description: >-
    api-docs, verbatim: "GET any paid path -> HTTP 402 + PAYMENT-REQUIRED header -> sign EIP-3009 USDC
    authorization on Base (eip155:8453) -> retry with X-PAYMENT header. No account, no API key." The 402
    observed live on 2026-09-19 carried an x402Version 1 JSON body plus PAYMENT-REQUIRED and WWW-Authenticate
    (MPP …) headers holding a base64 x402 v2 envelope, so both client generations are served. Rails: Base
    USDC (asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payTo 0xc91cE6291eDC0713ec753BAFBA002506ffb2b95c,
    scheme exact) and Solana USDC (payTo 2147pBT4LxoszjvLeGRxyVzpRnMi986VH3FAoprSs8Ez). Settlement via the
    Coinbase CDP facilitator; maxTimeoutSeconds 300.
  flow:
  - Request the paid route with no credential → 402 with requirements (price in atomic USDC, payTo, asset, network, maxTimeoutSeconds).
  - Sign an EIP-3009 transferWithAuthorization (Base) or an SPL transfer (Solana) for exactly maxAmountRequired.
  - Retry the identical request with X-PAYMENT or PAYMENT-SIGNATURE carrying the base64 payload → 200 with data.
  mcp_variant: 'the same payload is passed as the x_payment argument of a tools/call after a first call returns the requirements (initialize instructions, verbatim: "settle and retry with the signed payment payload in the x_payment argument")'
  sources:
  - https://store.agentexchange.work/api-docs
  - live 402 on GET https://store.agentexchange.work/chain/gas?chain=base (2026-09-19)
- name: Card-bought API key (optional)
  type: apiKey
  in: header
  parameter: 'Authorization: Bearer ak_… or X-API-Key'
  applied_to: every store SKU over plain HTTPS
  description: >-
    billing/catalog.json, verbatim: "Buy an API key with a credit/debit card. The key unlocks every SKU over
    plain HTTPS (send `Authorization: Bearer ak_...` or `X-API-Key`)." Plans: $29/month all-access, $19 one-time
    1,000-call pack, and a not-yet-purchasable $0.01/call metered plan; "Fair-use rate limited." The key prefix
    ak_ is the provider's own statement.
  sources:
  - https://store.agentexchange.work/billing/catalog.json
  - https://store.agentexchange.work/.well-known/usd.json
- name: Agent Planets api_key
  type: apiKey
  in: body
  parameter: api_key
  applied_to: planets mutating calls (terraform, build, post_offer, accept_offer …) and the $0.05 POST /api/accept
  description: 'Issued free on POST /api/claim ("Requires a planet api_key (free via POST /api/claim)" — planets x402 catalog). Identity for the claimed planet, not a paid credential.'
  sources:
  - https://planets.agentexchange.work/.well-known/x402
  - https://planets.agentexchange.work/llms.txt
- name: none (free surfaces)
  type: none
  applied_to: GET /score, /samples, /docs, /api-docs, /status, /health, /v1/models, /badge, /market/tasks, the Clearing House register/discover/bid routes, planets /pulse, /api/planets, /handshakes, oracle /oracle/info, and every discovery document
  description: Anonymous. CORS Access-Control-Allow-Origin * observed.
mcp:
  endpoint: https://store.agentexchange.work/mcp
  auth: none (initialize and tools/list anonymous); paid tools x402-gated per call via x_payment
  oauth_protected_resource: 404 — JSON body {"error":"not_oauth_protected", "authentication":{"type":"none","protocol":"x402","network":"base","asset":"USDC"}}
  dynamic_client_registration: not offered
attribution_headers:
  note: 'Optional, non-authenticating headers the /partners document defines for installed integrations: x-agent-store-client (stable integration name), x-agent-store-install-id (stored only as a one-way fingerprint after a paid call), x-agent-store-referrer (public referrer id). They identify an integration for attribution and never grant access.'
absent:
- OAuth 2.0 / OIDC (no discovery document on any of six hosts; the MCP host says so explicitly)
- mutual TLS
- signed requests beyond the x402 payment payload

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agentexchange-work-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.