APIMesh · Authentication Profile

Apimesh Xyz Authentication

Authentication

APIMesh secures its APIs with apiKey, x402, mpp, and none across 4 declared security schemes, as derived from its OpenAPI definitions.

Web AnalysisSEOWeb SecurityEmail VerificationDeveloper ToolsMicropaymentsx402MCPAgent-NativeWebhookAI Coding AgentsOpen SourceA2A
Methods: apiKey, x402, mpp, none Schemes: 4 OAuth flows: API key in: header

Security Schemes

apiKey http
scheme: bearer
x402 payment
mpp payment
none none

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://apimesh.xyz/.well-known/agent-card.json
docs:
- https://github.com/mbeato/APIMesh#payment-methods
- https://apimesh.xyz/llms-full.txt
- https://apimesh.xyz/.well-known/mpp
- https://apimesh.xyz/legal/terms
derived_from: openapi/_original/apimesh-xyz-openapi.json
note: >-
  Neither served OpenAPI declares a securityScheme (derive-authentication.py found none), so this
  profile is read from the documents that do describe access: the agent card's securitySchemes
  block, the MPP manifest's payment_methods, the README and llms-full.txt. The marketplace model
  was "pay, don't authenticate": an anonymous request to a paid endpoint received HTTP 402 with a
  WWW-Authenticate: Payment challenge and the client either paid per request (x402 USDC on Base,
  or Stripe MPP) or presented a prepaid-credit Bearer key. The two endpoints that are live today
  (agentsmd POST /normalize, stripesig POST /check) require no credential at all — confirmed
  2026-09-19 with anonymous 200/400 responses. The one authenticated write observed, PUT
  /wallet/{address}/cap, returned 401 anonymously and its credential type is undocumented.
summary:
  types: [apiKey, x402, mpp, none]
  api_key_in: [header]
  oauth2_flows: []
  live_surface_auth: none
schemes:
- name: apiKey
  type: http
  scheme: bearer
  header: Authorization
  key_prefix: sk_live_
  description: 'Prepaid-credit API key bought at https://apimesh.xyz/signup (Stripe Checkout); sent as Authorization: Bearer <key>. Each paid call deducts credits atomically before execution (RETIRED.md); credits never expire and are non-refundable (Terms §4).'
  purchase_url: https://apimesh.xyz/signup
  sources: [agent card securitySchemes.apiKey, https://apimesh.xyz/llms-full.txt]
  status: 'purchasable at /signup (200) but no priced endpoint answers since 2026-05-11'
- name: x402
  type: payment
  protocol: x402
  version: '1'
  network: base-mainnet (eip155:8453)
  asset: USDC
  facilitator: Coinbase CDP
  challenge: 'HTTP 402 with WWW-Authenticate: Payment carrying price, wallet and network; client signs a USDC transfer and retries with the X-PAYMENT header'
  discovery: [https://apimesh.xyz/.well-known/x402.json, https://apimesh.xyz/.well-known/x402]
  sources: [agent card securitySchemes.x402, https://github.com/mbeato/APIMesh#1-x402----crypto-micropayments-default]
- name: mpp
  type: payment
  protocol: mpp
  version: draft-ryan-httpauth-payment
  challenge: 'same HTTP 402 / WWW-Authenticate: Payment flow; cards and stablecoins via Stripe Machine Payments Protocol; discovery via OpenAPI x-mpp annotations (none present in the served specs) and per-API /.well-known/mpp'
  discovery: [https://apimesh.xyz/.well-known/mpp, https://agentsmd.apimesh.xyz/.well-known/mpp, https://stripesig.apimesh.xyz/.well-known/mpp]
  sources: [agent card securitySchemes.mpp, MPP manifest payment_methods]
- name: none
  type: none
  applies_to: ['POST https://agentsmd.apimesh.xyz/normalize', 'POST https://stripesig.apimesh.xyz/check', 'GET https://apimesh.xyz/wallet/{address}', 'GET https://apimesh.xyz/wallet/{address}/history', 'GET /health on every host']
  description: Anonymous; per-IP rate limits are the only gate.
  sources: [live probes 2026-09-19, https://github.com/mbeato/APIMesh#wallet--spend-tracking-free-no-auth]
mcp:
  handshake_auth: none
  environment: 'WALLET_PRIVATE_KEY (optional, secret) — funds x402 payments made by the tools; free /preview tools ran without it'
  source: mcp/apimesh-xyz-mcp.yml
oauth: false
openid_connect: false
discovery_probes:
- {url: https://apimesh.xyz/.well-known/oauth-authorization-server, status: 404}
- {url: https://apimesh.xyz/.well-known/oauth-protected-resource, status: 404}
- {url: https://apimesh.xyz/.well-known/openid-configuration, status: 404}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/apimesh-xyz-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.