AGENTUM · Authentication Profile
Agentum Lat Authentication
Authentication
AGENTUM declares 0 security scheme(s) across its OpenAPI definitions.
CompanyBusiness IntelligenceKYBCompany DataComplianceBrazilx402Agentic CommerceExchange RatesAddress VerificationEconomic DataMCPA2AAgents
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: https://agentum.lat/llms.txt
additional_docs:
- https://agentum.lat/ ("Sem conta, sem chave, sem assinatura: seu agente paga e recebe o resultado na mesma requisição")
- https://agentum.lat/openapi.json and https://business.agentum.lat/openapi.json (no securitySchemes, no security requirements; x-payment-info per operation)
- https://github.com/orionlabsai/agentum-mcp-server (README + index.js — how the provider's own client authorises a call)
- live 402 challenges on both hosts, 2026-09-19
summary:
types: []
http_schemes: []
api_key_in: []
oauth2_flows: []
credential_types: []
access_model: payment-gated, credential-less — x402 v2 per-request payment in USDC on Base mainnet stands in for authentication
public_operations: [GET https://business.agentum.lat/health, GET https://business.agentum.lat/ (service index), GET /openapi.json on both hosts, GET https://agentum.lat/llms.txt, GET /.well-known/agent-card.json and /.well-known/security.txt]
discovery: none — no RFC 8414 authorization-server metadata, no RFC 9728 protected-resource metadata, no OpenID configuration on any host (well-known/agentum-lat-well-known.yml). The machine-readable access contract is the 402 challenge itself.
dynamic_client_registration: false
delegated_identity: false
consent_identity: false
schemes: []
payment_gate:
protocol: x402 v2
scheme: exact
network: eip155:8453
asset: USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
challenge: HTTP 402 with PAYMENT-REQUIRED (base64 JSON PaymentRequirements) on every paid route; maxTimeoutSeconds 300
identity: the payer's on-chain address is the only identity the server sees; there is no account, session, key or token to issue, rotate or revoke
pay_to:
agentum_lat: '0xB4f9061e3a6A5533431336506b34e1035029599f'
business_agentum_lat: '0x7D1EDdfBd167787251fed83b250ABBeA1cf59a6F'
gate_order: the payment gate answers before input validation — malformed identifiers (cnpj=123, q=) received a 402, not the contract's 400
reference_client: '@agentum/mcp-server holds the CALLER''s wallet private key in env AGENTUM_MCP_WALLET_KEY and signs with @x402/fetch; the provider never issues or holds a credential'
agent_auth:
model: wallet-as-principal. An agent needs a funded Base wallet and an x402-capable client; nothing else. No scopes, no consent screen, no delegation — the wallet key IS full authority to spend, which the provider's README treats as the main risk (dedicated wallet, minimal balance, never commit the key).
human_in_the_loop: none at the protocol level; the provider's separate @agentum/x402-spend-guard library offers caller-side caps, allowlists and a kill switch
a2a_surface:
securitySchemes: >-
{} (empty) and securityRequirements [] in the agent card; the JSON-RPC root accepted an unauthenticated GetTask (answered -32001 TASK_NOT_FOUND). Whether paid skills are x402-gated over A2A was not observed.
notes:
- 'No OAuthScopes artifact is emitted: there is no OAuth surface. scopes/ is intentionally absent.'
- 'The derive-authentication.py pass produced no profile (0 securitySchemes across both specs), which is correct; this file was written by hand from the provider''s statements and the observed gate.'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/agentum-lat-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.