anchor-x402 · Authentication Profile

Anchor X402 Authentication

Authentication

anchor-x402 declares 2 security scheme(s) across its OpenAPI definitions.

Companyx402AgentsPaymentsBlockchainMCPWeb3pay-per-callAgentic PaymentsStablecoinsComplianceAttestationA2A
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

PAYMENT-SIGNATURE apiKey
· in: header ()
signature

Source

Authentication Profile

Raw ↑
generated: '2026-09-11'
method: searched
source: >-
  https://anchor-x402.com/llms.txt, https://api.anchor-x402.com/.well-known/agent-card.json,
  https://api.anchor-x402.com/.well-known/mcp/server-card.json, and a live 402 challenge observed at
  POST https://api.anchor-x402.com/v1/price/token
docs: https://anchor-x402.com/llms.txt
model: payment-as-authorization
accounts: false
api_keys: false
oauth: false
summary: >-
  There is no account, no registration, no API key and no bearer token anywhere in this API. Authorization
  IS payment. A request without a signed payment gets an HTTP 402 PaymentRequired carrying an accepts[]
  array of settlement options; the caller signs an EIP-3009 transferWithAuthorization for one of them and
  retries the identical request with the signed payload in a PAYMENT-SIGNATURE header. The x402 facilitator
  verifies and settles, and the service answers. Identity is a wallet, and it is presented per call rather
  than per session.
schemes:
- id: x402
  type: apiKey
  in: header
  name: PAYMENT-SIGNATURE
  legacy_name: X-PAYMENT
  legacy_note: The deprecated x402 V1 X-PAYMENT header spelling is still accepted alongside the V2 name.
  protocol: x402 v2
  applies_to: all 18 paid /v1/* routes and MCP tools/call
  description: >-
    x402 v2 pay-per-call. Modeled in the A2A agent card as an apiKey-in-header scheme because that is the
    closest A2A primitive; it is not a static credential - the header value is a signed, single-use,
    amount-bound payment authorization.
- id: a2a-ed25519-envelope
  type: signature
  applies_to: the four anchor-x402 extension methods on POST /v1/a2a (peer/hello, capabilities/list, peer/quote, peer/receipt)
  algorithm: ed25519
  digest: 'sha256:<hex> over compact key-sorted canonical JSON'
  signed_fields: [aud, body, exp, key_id, method, nonce, origin]
  audience: https://api.anchor-x402.com
  replay_protection:
    nonce: single-use, 8-128 chars
    exp_window_seconds: 300
  key_discovery: >-
    Peer identity bootstraps from DNS + TLS. A calling agent publishes an Ed25519 public key as a base64
    DER SubjectPublicKeyInfo in its own /.well-known/agent-card.json under any extensions.<namespace> block,
    either as a flat {key_id, public_key_der_base64} pair or a keys[] array for gapless rotation.
    anchor-x402 fetches that card and verifies against it. No human step and no registration.
  revocation: >-
    Delete the block or mark that key with a "status" of "retired"; either takes effect within 1h.
  server_keys:
    location: extensions["anchor-x402:a2a"].keys in the agent card
    custody: AWS KMS
    note: >-
      Two distinct key sets serve two jobs - signatures[] proves the card itself is authentic, while
      extensions["anchor-x402:a2a"].keys is what peers use to sign requests. The A2A spec has no field for
      the latter, which is why it lives in an extension.
  spec_methods_unsigned: >-
    The A2A spec methods themselves (message/send, tasks/get, tasks/cancel) are accepted unsigned, because a
    conformant A2A client will not produce this envelope; authorization there is the x402 payment.
settlement_rails:
- network: eip155:8453
  name: Base mainnet
  asset: USDC
  asset_contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'
  pay_to: '0x127462e296fAc1A7F5cF33bA57bB2f0FFf5cD0B6'
  facilitator: https://api.cdp.coinbase.com/platform/v2/x402
  max_timeout_seconds: 300
- network: 'solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp'
  name: Solana mainnet
  asset: USDC
  asset_contract: EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
  pay_to: 6apuZvJQ51Led9iEjnHw6f5jfnXL4qjt8S1h58PeXzuR
  fee_payer: CjNFTjvBhbJJd2B5ePPMHRLx1ELZpa8dwQgGL727eKww
  facilitator: https://api.cdp.coinbase.com/platform/v2/x402
  max_timeout_seconds: 300
- network: 'eip155:137'
  name: Polygon mainnet
  asset: JPYC
  asset_contract: '0x431D5dfF03120AFA4bDf332c61A6e1766eF37BDB'
  asset_decimals: 18
  pay_to: '0x127462e296fAc1A7F5cF33bA57bB2f0FFf5cD0B6'
  facilitator: in-process
  max_timeout_seconds: 300
  caveat: >-
    The yen amounts are fixed tiers, not a live FX conversion - pegged at an assumed ~JPY200/USD with no
    oracle, so the USD-equivalent of a JPYC payment floats against the USD price in both directions. The
    provider states this plainly in llms.txt rather than burying it.
free_and_anonymous:
- GET /health
- GET /openapi.json
- GET /docs
- GET /redoc
- POST /v1/attest/verify
- MCP server/discover, initialize and tools/list
- POST /v1/a2a spec methods and capabilities/list
spec_gap: >-
  openapi.json declares no components.securitySchemes and carries no security requirement on any operation,
  so the published OpenAPI reads as an entirely open API. Everything in this file was reconstructed from the
  agent card, the MCP server card, llms.txt and a live 402 response. A securitySchemes block naming the
  PAYMENT-SIGNATURE header would make the contract self-describing.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/anchor-x402-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.