Agent Bench · Authentication Profile

Agenthaven Dev Authentication

Authentication

Agent Bench secures its APIs with none and http-bearer-jwt across 2 declared security schemes, as derived from its OpenAPI definitions.

AgentsA2AMCPAgentic CommerceDNS-AIDTravelFlightsPaymentsAgent IdentityProof of ConceptAgent-Native
Methods: none, http-bearer-jwt Schemes: 2 OAuth flows: API key in:

Security Schemes

bearer http
scheme: bearer
anonymous none

Source

Authentication Profile

agenthaven-dev-authentication.yml Raw ↑
generated: '2026-09-19'
method: searched
source: https://travel.agenthaven.dev/.well-known/agent-card.json
docs:
- https://travel.agenthaven.dev/
- https://provedby.dev/contracts/guest-buyer.md
derived_from:
- a2a/agenthaven-dev-agent-card.json (securitySchemes, skills[].security)
- mcp/agenthaven-dev-mcp-tools.json (create_checkout inputSchema mandate_jws)
- https://travel.agenthaven.dev/health (guests policy, mandate_issuers)
note: >-
  derive-authentication.py was not run because the provider publishes no OpenAPI; the profile below is read
  from the agent card's securitySchemes (the only machine-readable auth declaration), the MCP initialize
  instructions (which repeat it verbatim), the documentation page, and the live /health document.
summary:
  types: [none, http-bearer-jwt]
  api_key_in: []
  oauth2_flows: []
  token_endpoint: none published
  discovery: none (no RFC 8414 / OIDC / RFC 9728 documents on any host)
  anonymous_surface: [MCP initialize, MCP ping, MCP tools/list, MCP tools/call search_flights, A2A message/send search_flights, GET /health, GET /ledger, every /.well-known document]
  authenticated_surface: [MCP tools/call create_checkout, A2A message/send create_checkout]
  delegation_model: >-
    Buyer-side mandates rather than OAuth authorization_code. The docs state the checkout token "carries a
    spending cap, a currency and a deadline set by the buyer's human; a request above the cap is refused, and
    the refusal is written to the ledger" — a delegated, human-bounded authority — but it is expressed as a
    JWT mandate from an issuer the merchant trusts, not as a token obtained through an authorization server, so
    no discovery document exists for the rubric's delegated_identity check to read.
schemes:
- name: bearer
  type: http
  scheme: bearer
  bearerFormat: JWT
  required_for: [create_checkout]
  scopes: [commerce:purchase]
  sources: ['a2a/agenthaven-dev-agent-card.json#securitySchemes.bearer', 'a2a/agenthaven-dev-agent-card.json#skills[1].security']
  description: >-
    "Needed for create_checkout only; search_flights and tools/list are open. There is no public token endpoint.
    Two forms are accepted. (1) Sign each call as a request envelope (Authorization: Bearer <compact JWS, typ
    request+jwt>) under a key attested at /.well-known/agent-keys.json on your own domain, and present at
    checkout a mandate from an authority this merchant trusts (https://sealedby.dev), bound to the quote and to
    that key. (2) A JWT issued by this merchant's operator on request: iss agent-bench-demo-issuer, aud
    agent-bench, scope commerce:purchase, with a spending cap in EUR."
  forms:
  - id: request-envelope
    how: Per-call compact JWS with typ request+jwt in the Authorization header, signed by the caller's own key.
    key_attestation: 'The signing key is attested at /.well-known/agent-keys.json on the CALLER''s domain (the merchant does not serve one for itself; travel.agenthaven.dev/.well-known/agent-keys.json 404).'
    mandate: 'At checkout, mandate_jws (typ mandate+jwt) from a trusted authority — GET /health lists mandate_issuers ["https://sealedby.dev"] — bound to quote_hash and to the envelope key; ledger entries record mandate_format ap2-v0.2.'
  - id: operator-issued-jwt
    how: A JWT the merchant's operator issues on request (no self-service path). Claims stated by the card — iss agent-bench-demo-issuer, aud agent-bench, scope commerce:purchase, plus an EUR spending cap.
  - id: guest-buyer
    how: >-
      Documented on the page under "Buying as a guest": a buyer with no introduction publishes a P-256 public
      key in a DNSSEC-signed TXT record at _agent-keys.<its domain> ("v=agentkey1; kty=EC; crv=P-256; x=...;
      y=..."), signs each call as a request envelope with iss spiffe://<its domain>/<any path>, and presents a
      mandate it issues itself (typ mandate+jwt, iss https://<its domain>, signed by a key in that record,
      bound to the quote and the envelope key, living at most 10 minutes).
    limits: 'GET /health guests: accepted true, ceiling_minor 100000 EUR (1000.00 EUR per purchase), mandate_max_seconds 600, purchases_per_day 20 (all guests together); guest searches spend the anonymous budget. Contract, vector and a one-file reference buyer at https://provedby.dev/contracts/guest-buyer.md (200, third-party host named by the provider).'
- name: anonymous
  type: none
  applies_to: [search_flights, tools/list, initialize, ping, /health, /ledger, well-known documents]
  limits: anonymous searches 40 per day and 120 per month, shared; an authorised search never counts (docs; live counters in GET /health counters.anonymous_searches).
  sources: [https://travel.agenthaven.dev/, https://travel.agenthaven.dev/health]
verification_keys:
  merchant_jwks: https://travel.agenthaven.dev/.well-known/jwks.json
  merchant_jwks_note: 'Documented as "Authorization key set — public keys the merchant verifies buyer tokens against" (kid eF_VZyTpOBYDR0TXuvJF0nALLjaWIHQYWQhgbPZzMnM, ES256).'
  instance_svid: https://travel.agenthaven.dev/.well-known/spiffe-svid.json
  trust_bundle: https://travel.agenthaven.dev/.well-known/spiffe-bundle.json
  dns_aid_record_key: https://dns-aid.agenthaven.dev/.well-known/dns-aid-jwks.json
refusals: See errors/agenthaven-dev-problem-types.yml — authorization_missing, authorization_invalid, authorization_denied, signer_unknown, identity_revoked, mandate_expired, mandate_consumed, mandate_revoked and quote_hash_mismatch are the auth-stage refusal reasons observed in the public ledger.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agenthaven-dev-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.