Agent Health Monitor · Authentication Profile

Agenthealthmonitor Xyz Authentication

Authentication

Agent Health Monitor secures its APIs with apiKey, x402-payment, internal-key, and coupon across 4 declared security schemes, as derived from its OpenAPI definitions.

AgentsAgent TrustRisk ScoringWallet IntelligenceBlockchainBasex402Agentic CommerceMonitoringWebhookWeb3Verifiable CredentialsDeveloper ToolsAgent-NativeA2A
Methods: apiKey, x402-payment, internal-key, coupon Schemes: 4 OAuth flows: API key in: header

Security Schemes

ApiKeyAuth apiKey
· in: header (X-API-Key)
X402Payment x402
scheme: exact · in: header (X-PAYMENT (request) / PAYMENT-REQUIRED (402 challenge response))
InternalKey apiKey
· in: header (X-Internal-Key)
CouponCode path-token
· in: path ({code} in /coupon/{action}/{code}/{address})

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/agenthealthmonitor-xyz-openapi.yml and openapi/agenthealthmonitor-xyz-verify-openapi.yml (NEITHER declares
  components.securitySchemes or security[] — derive-authentication.py produced nothing, so this profile is built from the
  docs and live probes)
docs: https://docs.agenthealthmonitor.xyz/#gs-api
additional_docs:
- https://docs.agenthealthmonitor.xyz/#integration
- https://github.com/moonshot-cyber/agent-health-monitor#stripe-fiat--no-wallet-required
- https://agenthealthmonitor.xyz/.well-known/x402
- openapi info.description (Payment / Free preview / Coupon access paragraphs)
summary:
  types:
  - apiKey
  - x402-payment
  - internal-key
  - coupon
  http_schemes: []
  api_key_in:
  - header
  oauth2_flows: []
  openid_connect: false
  mutual_tls: false
  credential_types:
  - ahm_live_ API key (Stripe credit pack or subscription)
  - x402 v2 payment proof (X-PAYMENT header) — USDC on eip155:8453
  - X-Internal-Key (operator only)
  - partner coupon code in the URL path
  public_operations:
  - api_info_api_info_get
  - ecosystem_stats_api_ecosystem_stats_get
  - leaderboard_api_leaderboard_get
  - get_agent_public_api_agent__address__get
  - endpoint_info_api_endpoint_info__slug__get
  - retry_preview_retry_preview__address__get
  - protection_preview_agent_protect_preview__address__get
  - alert_status_alerts_status__address__get
  - configure_alerts_alerts_configure_post
  - unsubscribe_alerts_alerts_unsubscribe__address__delete
  - up_up_get
  - a2a_agent_card__well_known_agent_json_get
  - x402_discovery__well_known_x402_get
  - agent_registration__well_known_agent_registration_json_get
  - create_spec_v1_specs_post (Verify)
  - get_verdict_v1_verdicts__verdict_id__get (Verify)
  - health_health_get (Verify)
  discovery: None of RFC 9728 / RFC 8414 / OIDC. The only machine-readable auth discovery is the x402 402 challenge itself
    (PAYMENT-REQUIRED header) and /.well-known/x402.
  dynamic_client_registration: false
  delegated_identity: false
  agent_onboarding: Fully autonomous via x402 — an agent with a funded Base wallet needs no account, key or human step; the
    fiat path needs a human to pay via Stripe and paste the key.
schemes:
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter: X-API-Key
  sources:
  - https://docs.agenthealthmonitor.xyz/#gs-api
  - README
  applies_to: every paid operation as an alternative to x402 (the source lists the X-API-Key bypass paths); required on api_key_status_api_key_status_get
    and partner_usage_partners__partner_id__usage_get
  header: 'X-API-Key: ahm_live_<secret>'
  key_format: ahm_live_ prefix (README, SDK examples, source); the docs quick-start shows ahm_sk_… — treat ahm_live_ as authoritative.
    Keys are credit-metered (Starter 100 / Pro 500 calls) or unlimited on the $99/month subscription; stored server-side and
    validated per request.
  issuance: Stripe payment links on https://agenthealthmonitor.xyz/pay-by-card; after checkout the key is retrieved once at
    GET /stripe/key/{session_id} (retrieve_key_stripe_key__session_id__get). Also via the design-partner programme.
  rotation: Not documented. No revoke/rotate operation in the API.
  errors:
    '401': '{"detail":"X-API-Key header required"} / {"detail":"Invalid or expired API key"}'
    '429': '{"detail":"API key calls exhausted"}'
  observed: GET https://agenthealthmonitor.xyz/api/key/status -> 401 {"detail":"X-API-Key header required"} (2026-09-19)
- name: X402Payment
  type: x402
  version: 2
  in: header
  parameter: X-PAYMENT (request) / PAYMENT-REQUIRED (402 challenge response)
  sources:
  - https://agenthealthmonitor.xyz/.well-known/x402
  - live 402 on GET /risk/{address}, GET /ahs/route/policy, POST verify /v1/outputs
  applies_to: the 15 payable resources in /.well-known/x402 (all 14 documented endpoints plus PUT /ahs/route/policy) and AHM
    Verify POST /v1/outputs
  network: eip155:8453 (Base mainnet)
  asset: USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 (EIP-712 domain name "USD Coin" version "2")
  scheme: exact
  pay_to:
    main_api: '0xaD64EFCe9CfeE4d1D1701d9a0009CCa72B9ff000'
    ahm_verify: '0x23A2e9Cd7F0a602A3FcFFaf8074113A9205726E5'
  facilitator: https://facilitator.payai.network
  max_timeout_seconds: 300
  flow: 1) call the endpoint; 2) receive 402 with body {} and PAYMENT-REQUIRED = base64 JSON {x402Version 2, error "Payment
    required", resource{url, description, mimeType}, accepts[{scheme, network, asset, amount, payTo, maxTimeoutSeconds, extra}],
    extensions.bazaar}; 3) sign an EIP-3009 transferWithAuthorization for accepts[0]; 4) resend with X-PAYMENT; the facilitator
    verifies and settles.
  identity: 'The payer wallet address becomes the caller identity for stateful routes (routing policy owner, batch limits)
    — "x402 callers: owner_id = lowercased payer wallet" in source.'
  observed: GET /risk/0x0000000000000000000000000000000000000001 -> 402, accepts[0].amount 1000 (= $0.001); GET /ahs/route/policy
    -> 402 amount 10000; POST https://verify.agenthealthmonitor.xyz/v1/outputs -> 402 amount 500000 (2026-09-19)
- name: InternalKey
  type: apiKey
  in: header
  parameter: X-Internal-Key
  sources:
  - 'openapi operation descriptions (Admin tag: "Protected by X-Internal-Key header. Not accessible via x402 payment.")'
  applies_to:
  - security_activity_security_activity_get
  - trust_registry_trust_registry_get
  - internal_agent_profile_internal_agent_profile__address__get
  - trigger_acp_scan_acp_scan_trigger_post
  - acp_scan_status_acp_scan_status_get
  - trigger_olas_scan_olas_scan_trigger_post
  - olas_scan_status_olas_scan_status_get
  - trigger_arc_scan_arc_scan_trigger_post
  - arc_scan_status_arc_scan_status_get
  - trigger_celo_scan_celo_scan_trigger_post
  - celo_scan_status_celo_scan_status_get
  - trigger_erc8004_scan_erc8004_scan_trigger_post
  - erc8004_scan_status_erc8004_scan_status_get
  - erc8183_status_erc8183_status_get
  note: Operator-only; also bypasses x402 on paid routes (source). Not obtainable by customers.
  observed: GET /trust-registry -> 401 {"detail":"Unauthorized"}
- name: CouponCode
  type: path-token
  in: path
  parameter: '{code} in /coupon/{action}/{code}/{address}'
  sources:
  - 'openapi info.description: "partners can use coupon codes to access any paid endpoint without x402 payment"'
  applies_to:
  - validate_coupon_coupon_validate__code__get
  - coupon_risk_coupon_risk__code___address__get
  - coupon_health_coupon_health__code___address__get
  - coupon_optimize_coupon_optimize__code___address__get
  - coupon_retry_coupon_retry__code___address__get
  - coupon_protect_coupon_protect__code___address__get
  - coupon_alerts_coupon_alerts__code___address__get
  - coupon_premium_risk_coupon_risk_premium__code___address__get
  - coupon_counterparties_coupon_counterparties__code___address__get
  - coupon_network_map_coupon_network_map__code___address__get
  - coupon_wash_coupon_wash__code___address__get
  - coupon_ahs_coupon_ahs__code___address__get
  - coupon_report_card_coupon_report_card__code___address__get
  note: Partner-issued codes; rate-limited to 5 attempts per window on validation and access (source). A credential in the
    URL path, so it appears in logs and caches.
agent_card_auth:
  note: The A2A card (a2a/agenthealthmonitor-xyz-agent-card.json) declares bearerAuth (http bearer, JWT) and an apiKey header
    named X-AHM-API-Key — neither matches the deployed REST API, which uses X-API-Key and no bearer tokens; the A2A endpoint
    the card protects is not deployed.
sdk:
  ahm-shield: AHMShield(api_key="ahm_live_...") sends X-API-Key; no x402 support in the SDK (an agent paying with x402 uses
    an x402 HTTP client instead).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agenthealthmonitor-xyz-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.