anchor-x402 · Authentication Profile
Anchor X402 Authentication
Authentication
anchor-x402 declares 2 security scheme(s) across its OpenAPI definitions.
Companyx402AgentsPaymentsBlockchainMCPWeb3pay-per-callAgentic PaymentsStablecoinsComplianceAttestationA2A
Methods:
Schemes: 2
OAuth flows:
API key in:
Security Schemes
PAYMENT-SIGNATURE apiKey
· in: header ()
signature
Source
Authentication Profile
generated: '2026-09-11'
method: searched
source: >-
https://anchor-x402.com/llms.txt, https://api.anchor-x402.com/.well-known/agent-card.json,
https://api.anchor-x402.com/.well-known/mcp/server-card.json, and a live 402 challenge observed at
POST https://api.anchor-x402.com/v1/price/token
docs: https://anchor-x402.com/llms.txt
model: payment-as-authorization
accounts: false
api_keys: false
oauth: false
summary: >-
There is no account, no registration, no API key and no bearer token anywhere in this API. Authorization
IS payment. A request without a signed payment gets an HTTP 402 PaymentRequired carrying an accepts[]
array of settlement options; the caller signs an EIP-3009 transferWithAuthorization for one of them and
retries the identical request with the signed payload in a PAYMENT-SIGNATURE header. The x402 facilitator
verifies and settles, and the service answers. Identity is a wallet, and it is presented per call rather
than per session.
schemes:
- id: x402
type: apiKey
in: header
name: PAYMENT-SIGNATURE
legacy_name: X-PAYMENT
legacy_note: The deprecated x402 V1 X-PAYMENT header spelling is still accepted alongside the V2 name.
protocol: x402 v2
applies_to: all 18 paid /v1/* routes and MCP tools/call
description: >-
x402 v2 pay-per-call. Modeled in the A2A agent card as an apiKey-in-header scheme because that is the
closest A2A primitive; it is not a static credential - the header value is a signed, single-use,
amount-bound payment authorization.
- id: a2a-ed25519-envelope
type: signature
applies_to: the four anchor-x402 extension methods on POST /v1/a2a (peer/hello, capabilities/list, peer/quote, peer/receipt)
algorithm: ed25519
digest: 'sha256:<hex> over compact key-sorted canonical JSON'
signed_fields: [aud, body, exp, key_id, method, nonce, origin]
audience: https://api.anchor-x402.com
replay_protection:
nonce: single-use, 8-128 chars
exp_window_seconds: 300
key_discovery: >-
Peer identity bootstraps from DNS + TLS. A calling agent publishes an Ed25519 public key as a base64
DER SubjectPublicKeyInfo in its own /.well-known/agent-card.json under any extensions.<namespace> block,
either as a flat {key_id, public_key_der_base64} pair or a keys[] array for gapless rotation.
anchor-x402 fetches that card and verifies against it. No human step and no registration.
revocation: >-
Delete the block or mark that key with a "status" of "retired"; either takes effect within 1h.
server_keys:
location: extensions["anchor-x402:a2a"].keys in the agent card
custody: AWS KMS
note: >-
Two distinct key sets serve two jobs - signatures[] proves the card itself is authentic, while
extensions["anchor-x402:a2a"].keys is what peers use to sign requests. The A2A spec has no field for
the latter, which is why it lives in an extension.
spec_methods_unsigned: >-
The A2A spec methods themselves (message/send, tasks/get, tasks/cancel) are accepted unsigned, because a
conformant A2A client will not produce this envelope; authorization there is the x402 payment.
settlement_rails:
- network: eip155:8453
name: Base mainnet
asset: USDC
asset_contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'
pay_to: '0x127462e296fAc1A7F5cF33bA57bB2f0FFf5cD0B6'
facilitator: https://api.cdp.coinbase.com/platform/v2/x402
max_timeout_seconds: 300
- network: 'solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp'
name: Solana mainnet
asset: USDC
asset_contract: EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
pay_to: 6apuZvJQ51Led9iEjnHw6f5jfnXL4qjt8S1h58PeXzuR
fee_payer: CjNFTjvBhbJJd2B5ePPMHRLx1ELZpa8dwQgGL727eKww
facilitator: https://api.cdp.coinbase.com/platform/v2/x402
max_timeout_seconds: 300
- network: 'eip155:137'
name: Polygon mainnet
asset: JPYC
asset_contract: '0x431D5dfF03120AFA4bDf332c61A6e1766eF37BDB'
asset_decimals: 18
pay_to: '0x127462e296fAc1A7F5cF33bA57bB2f0FFf5cD0B6'
facilitator: in-process
max_timeout_seconds: 300
caveat: >-
The yen amounts are fixed tiers, not a live FX conversion - pegged at an assumed ~JPY200/USD with no
oracle, so the USD-equivalent of a JPYC payment floats against the USD price in both directions. The
provider states this plainly in llms.txt rather than burying it.
free_and_anonymous:
- GET /health
- GET /openapi.json
- GET /docs
- GET /redoc
- POST /v1/attest/verify
- MCP server/discover, initialize and tools/list
- POST /v1/a2a spec methods and capabilities/list
spec_gap: >-
openapi.json declares no components.securitySchemes and carries no security requirement on any operation,
so the published OpenAPI reads as an entirely open API. Everything in this file was reconstructed from the
agent card, the MCP server card, llms.txt and a live 402 response. A securitySchemes block naming the
PAYMENT-SIGNATURE header would make the contract self-describing.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/anchor-x402-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.