Agent Health Monitor · Authentication Profile
Agenthealthmonitor Xyz Authentication
Authentication
Agent Health Monitor secures its APIs with apiKey, x402-payment, internal-key, and coupon across 4 declared security schemes, as derived from its OpenAPI definitions.
AgentsAgent TrustRisk ScoringWallet IntelligenceBlockchainBasex402Agentic CommerceMonitoringWebhookWeb3Verifiable CredentialsDeveloper ToolsAgent-NativeA2A
Methods: apiKey, x402-payment, internal-key, coupon
Schemes: 4
OAuth flows:
API key in: header
Security Schemes
ApiKeyAuth apiKey
· in: header (X-API-Key)
X402Payment x402
scheme: exact
· in: header (X-PAYMENT (request) / PAYMENT-REQUIRED (402 challenge response))
InternalKey apiKey
· in: header (X-Internal-Key)
CouponCode path-token
· in: path ({code} in /coupon/{action}/{code}/{address})
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/agenthealthmonitor-xyz-openapi.yml and openapi/agenthealthmonitor-xyz-verify-openapi.yml (NEITHER declares
components.securitySchemes or security[] — derive-authentication.py produced nothing, so this profile is built from the
docs and live probes)
docs: https://docs.agenthealthmonitor.xyz/#gs-api
additional_docs:
- https://docs.agenthealthmonitor.xyz/#integration
- https://github.com/moonshot-cyber/agent-health-monitor#stripe-fiat--no-wallet-required
- https://agenthealthmonitor.xyz/.well-known/x402
- openapi info.description (Payment / Free preview / Coupon access paragraphs)
summary:
types:
- apiKey
- x402-payment
- internal-key
- coupon
http_schemes: []
api_key_in:
- header
oauth2_flows: []
openid_connect: false
mutual_tls: false
credential_types:
- ahm_live_ API key (Stripe credit pack or subscription)
- x402 v2 payment proof (X-PAYMENT header) — USDC on eip155:8453
- X-Internal-Key (operator only)
- partner coupon code in the URL path
public_operations:
- api_info_api_info_get
- ecosystem_stats_api_ecosystem_stats_get
- leaderboard_api_leaderboard_get
- get_agent_public_api_agent__address__get
- endpoint_info_api_endpoint_info__slug__get
- retry_preview_retry_preview__address__get
- protection_preview_agent_protect_preview__address__get
- alert_status_alerts_status__address__get
- configure_alerts_alerts_configure_post
- unsubscribe_alerts_alerts_unsubscribe__address__delete
- up_up_get
- a2a_agent_card__well_known_agent_json_get
- x402_discovery__well_known_x402_get
- agent_registration__well_known_agent_registration_json_get
- create_spec_v1_specs_post (Verify)
- get_verdict_v1_verdicts__verdict_id__get (Verify)
- health_health_get (Verify)
discovery: None of RFC 9728 / RFC 8414 / OIDC. The only machine-readable auth discovery is the x402 402 challenge itself
(PAYMENT-REQUIRED header) and /.well-known/x402.
dynamic_client_registration: false
delegated_identity: false
agent_onboarding: Fully autonomous via x402 — an agent with a funded Base wallet needs no account, key or human step; the
fiat path needs a human to pay via Stripe and paste the key.
schemes:
- name: ApiKeyAuth
type: apiKey
in: header
parameter: X-API-Key
sources:
- https://docs.agenthealthmonitor.xyz/#gs-api
- README
applies_to: every paid operation as an alternative to x402 (the source lists the X-API-Key bypass paths); required on api_key_status_api_key_status_get
and partner_usage_partners__partner_id__usage_get
header: 'X-API-Key: ahm_live_<secret>'
key_format: ahm_live_ prefix (README, SDK examples, source); the docs quick-start shows ahm_sk_… — treat ahm_live_ as authoritative.
Keys are credit-metered (Starter 100 / Pro 500 calls) or unlimited on the $99/month subscription; stored server-side and
validated per request.
issuance: Stripe payment links on https://agenthealthmonitor.xyz/pay-by-card; after checkout the key is retrieved once at
GET /stripe/key/{session_id} (retrieve_key_stripe_key__session_id__get). Also via the design-partner programme.
rotation: Not documented. No revoke/rotate operation in the API.
errors:
'401': '{"detail":"X-API-Key header required"} / {"detail":"Invalid or expired API key"}'
'429': '{"detail":"API key calls exhausted"}'
observed: GET https://agenthealthmonitor.xyz/api/key/status -> 401 {"detail":"X-API-Key header required"} (2026-09-19)
- name: X402Payment
type: x402
version: 2
in: header
parameter: X-PAYMENT (request) / PAYMENT-REQUIRED (402 challenge response)
sources:
- https://agenthealthmonitor.xyz/.well-known/x402
- live 402 on GET /risk/{address}, GET /ahs/route/policy, POST verify /v1/outputs
applies_to: the 15 payable resources in /.well-known/x402 (all 14 documented endpoints plus PUT /ahs/route/policy) and AHM
Verify POST /v1/outputs
network: eip155:8453 (Base mainnet)
asset: USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 (EIP-712 domain name "USD Coin" version "2")
scheme: exact
pay_to:
main_api: '0xaD64EFCe9CfeE4d1D1701d9a0009CCa72B9ff000'
ahm_verify: '0x23A2e9Cd7F0a602A3FcFFaf8074113A9205726E5'
facilitator: https://facilitator.payai.network
max_timeout_seconds: 300
flow: 1) call the endpoint; 2) receive 402 with body {} and PAYMENT-REQUIRED = base64 JSON {x402Version 2, error "Payment
required", resource{url, description, mimeType}, accepts[{scheme, network, asset, amount, payTo, maxTimeoutSeconds, extra}],
extensions.bazaar}; 3) sign an EIP-3009 transferWithAuthorization for accepts[0]; 4) resend with X-PAYMENT; the facilitator
verifies and settles.
identity: 'The payer wallet address becomes the caller identity for stateful routes (routing policy owner, batch limits)
— "x402 callers: owner_id = lowercased payer wallet" in source.'
observed: GET /risk/0x0000000000000000000000000000000000000001 -> 402, accepts[0].amount 1000 (= $0.001); GET /ahs/route/policy
-> 402 amount 10000; POST https://verify.agenthealthmonitor.xyz/v1/outputs -> 402 amount 500000 (2026-09-19)
- name: InternalKey
type: apiKey
in: header
parameter: X-Internal-Key
sources:
- 'openapi operation descriptions (Admin tag: "Protected by X-Internal-Key header. Not accessible via x402 payment.")'
applies_to:
- security_activity_security_activity_get
- trust_registry_trust_registry_get
- internal_agent_profile_internal_agent_profile__address__get
- trigger_acp_scan_acp_scan_trigger_post
- acp_scan_status_acp_scan_status_get
- trigger_olas_scan_olas_scan_trigger_post
- olas_scan_status_olas_scan_status_get
- trigger_arc_scan_arc_scan_trigger_post
- arc_scan_status_arc_scan_status_get
- trigger_celo_scan_celo_scan_trigger_post
- celo_scan_status_celo_scan_status_get
- trigger_erc8004_scan_erc8004_scan_trigger_post
- erc8004_scan_status_erc8004_scan_status_get
- erc8183_status_erc8183_status_get
note: Operator-only; also bypasses x402 on paid routes (source). Not obtainable by customers.
observed: GET /trust-registry -> 401 {"detail":"Unauthorized"}
- name: CouponCode
type: path-token
in: path
parameter: '{code} in /coupon/{action}/{code}/{address}'
sources:
- 'openapi info.description: "partners can use coupon codes to access any paid endpoint without x402 payment"'
applies_to:
- validate_coupon_coupon_validate__code__get
- coupon_risk_coupon_risk__code___address__get
- coupon_health_coupon_health__code___address__get
- coupon_optimize_coupon_optimize__code___address__get
- coupon_retry_coupon_retry__code___address__get
- coupon_protect_coupon_protect__code___address__get
- coupon_alerts_coupon_alerts__code___address__get
- coupon_premium_risk_coupon_risk_premium__code___address__get
- coupon_counterparties_coupon_counterparties__code___address__get
- coupon_network_map_coupon_network_map__code___address__get
- coupon_wash_coupon_wash__code___address__get
- coupon_ahs_coupon_ahs__code___address__get
- coupon_report_card_coupon_report_card__code___address__get
note: Partner-issued codes; rate-limited to 5 attempts per window on validation and access (source). A credential in the
URL path, so it appears in logs and caches.
agent_card_auth:
note: The A2A card (a2a/agenthealthmonitor-xyz-agent-card.json) declares bearerAuth (http bearer, JWT) and an apiKey header
named X-AHM-API-Key — neither matches the deployed REST API, which uses X-API-Key and no bearer tokens; the A2A endpoint
the card protects is not deployed.
sdk:
ahm-shield: AHMShield(api_key="ahm_live_...") sends X-API-Key; no x402 support in the SDK (an agent paying with x402 uses
an x402 HTTP client instead).
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agenthealthmonitor-xyz-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.