Priorflow · Authentication Profile
Agentopt App Authentication
Authentication
Priorflow secures its APIs with apiKey and http-bearer across 2 declared security schemes, as derived from its OpenAPI definitions.
AI AgentsAgent DiscoveryAgent SelectionA2AMCPAgent OrchestrationTool RankingSemantic SearchAgent-Native
Methods: apiKey, http-bearer
Schemes: 2
OAuth flows:
API key in: header
Security Schemes
apiKey apiKey
· in: header (X-API-Key)
bearer http
scheme: bearer
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: https://agentopt.app/.well-known/agent-card.json
docs:
- https://agentopt.app/info
- https://agentopt.app/upgrade
summary:
types:
- apiKey
- http-bearer
api_key_in:
- header
oauth2_flows: []
bearer: true
credential_classes: 2
headline: >-
Two tiers, one credential. The free tier needs no credential at all — only a non-empty User-Agent header
and, by convention, a stable caller_agent string in the body — and is open on this host while
require_api_key is false (confirmed live via GET /ready). The paid tier uses a key sent as X-API-Key,
or equivalently as Authorization: Bearer; keys are issued to a human "sponsor" once (Stripe Checkout at
POST /v1/billing/checkout, one-time reveal at GET /v1/billing/session/{session_id}/key, or minted by the
operator) and agents use them autonomously thereafter. Invalid keys always return 401; paid-only
features without a key return 402 upgrade_required. No OAuth, no OIDC, no discovery documents.
schemes:
- name: apiKey
type: apiKey
in: header
parameter: X-API-Key
description: 'Paid-tier API key. Free tier works without a key (limited fields). Invalid keys are rejected. (verbatim from the agent card securitySchemes.apiKey.description)'
key_prefix: pf_live_
key_prefix_evidence: 'The /upgrade page example reads X-API-Key: pf_live_… and the /try page labels its operator-published evaluation key with the same prefix.'
issuance:
mode: checkout
summary: 'POST /v1/billing/checkout then reveal key once via GET /v1/billing/session/{session_id}/key; agents use X-API-Key thereafter. (verbatim, agent card priorflow.upgrade.obtain.summary)'
checkout_operation: POST https://agentopt.app/v1/billing/checkout
checkout_body_example: '{"customer_email":"sponsor@example.com","client_reference_id":"tenant-1"}'
reveal_operation: 'GET https://agentopt.app/v1/billing/session/{session_id}/key (one-time)'
human_return_url: 'https://agentopt.app/upgrade/success?session_id=…'
operator_issued: 'Operators can still mint keys with create_api_key.py. (verbatim, /upgrade)'
docs: https://agentopt.app/upgrade
used_by: ['POST /v1/select (paid tier: unlocks tags, dimensions, score_breakdown, recommendation, clarifications, source_url, endpoint/connect, homepage_url, endpoint_status; top_n up to 20; include_explanations)']
sources:
- a2a/agentopt-app-agent-card.json
- https://agentopt.app/upgrade
- name: bearer
type: http
scheme: bearer
description: 'Also accepted: Authorization: Bearer …. Invalid keys always return 401. (verbatim, /upgrade "How agents use paid access")'
note: The same pf_live_ key carried as a bearer token instead of X-API-Key. Declared only in the card's legacy authentication block (schemes [Bearer, ApiKey]) and on the /upgrade page, not in securitySchemes.
sources:
- a2a/agentopt-app-agent-card.json
- https://agentopt.app/upgrade
anonymous_access:
allowed: true
evidence: 'agent card security: [] and priorflow.api.select.require_api_key false; /ready require_api_key false (fetched 2026-09-19)'
conditions:
- 'Requires non-empty User-Agent on free calls. (card, select-agents skill)'
- 'Always send a non-empty User-Agent and a stable caller_agent. (/info, Integrate)'
- 'Free tier returns id, score, score_band, name only; top_n <= 5; lower RPM (roughly 20/min, 120/hour, 500/day per IP).'
- 'The operator can close the free tier: "free tier open on this host when enabled".'
failure_semantics:
invalid_key: 401 (always)
paid_feature_without_key: 402 upgrade_required (when enabled)
exhausted_pack: 402 select_quota_exceeded or api_key_expired
detail: errors/agentopt-app-problem-types.yml
not_present:
oauth2: false
oidc: false
mutual_tls: false
discovery_documents: '/.well-known/oauth-authorization-server and /.well-known/openid-configuration both 404 (well-known/agentopt-app-well-known.yml)'
note: >-
No OpenAPI exists to derive from, so derive-authentication.py had nothing to read; this profile is
searched from the agent card's securitySchemes and the /info and /upgrade pages. The evaluation key the
operator publishes on /try is deliberately NOT recorded here or anywhere in this repo — it is a live paid
credential drawn from a shared, expiring quota pool, not a test-mode value (see sandbox/).
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agentopt-app-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.