Berrer · Authentication Profile

Berrergate Com Authentication

Authentication

Berrer declares 0 security scheme(s) across its OpenAPI definitions.

AgentsAgentic CommerceA2AMCPx402ProcurementTool DiscoveryAPI DiscoveryInferenceResearchAgent-Native
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://api.berrergate.com/llms.txt
derived_from: openapi/berrergate-com-openapi.json
docs:
- https://api.berrergate.com/skill.md
- https://api.berrergate.com/.well-known/x402.json
summary: >-
  BerrerGate has NO authentication scheme: the OpenAPI declares no securitySchemes and no security
  requirement, the A2A card declares securitySchemes {} and securityRequirements [], and no OAuth/OIDC
  metadata is served on any host. Every read route and the free preview POSTs answer anonymously. Access to
  the paid routes is gated economically, per request, by x402 payment: the first call returns HTTP 402 with
  PaymentRequirements, and the retry carries a PAYMENT-SIGNATURE header settling USDC on Base. There are no
  accounts, API keys, tokens or signups ("without creating a traditional account"). derive-authentication.py
  produced no profile because the contract declares nothing; this file was written from the observed
  requests and the provider's own docs.
schemes: []
access_model:
  anonymous_reads: true
  anonymous_free_writes: ['POST /v1/agent/procurement/preview', 'POST /v1/agent/discovery/preview', 'POST /v1/agent/trial/query (free, x-idempotency-key required)', 'POST /a2a/jsonrpc', 'POST /a2a/v1/message:send']
  payment_gated_writes: ['POST /v1/research ($0.020)', 'POST /v1/agent/beta/query ($0.01)', 'POST /v1/agent/utility/inference ($0.00125-$0.00225 dynamic)', 'POST /v1/agent/utility/spend-router ($0.001, currently disabled)', 'GET /v1/agent/canary/browser-automation-select ($0.01 one-shot)']
  payment:
    protocol: x402
    version: 2
    request_header: PAYMENT-SIGNATURE
    challenge_header: PAYMENT-REQUIRED
    response_header: PAYMENT-RESPONSE
    scheme: exact
    network: eip155:8453 (Base mainnet)
    asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 (USD Coin, version 2)'
    pay_to: '0x1090DDAf854Ff0f6A65F24a866C29C46fdDa0a8a'
    max_timeout_seconds: 60
    observed: 'POST /v1/research -> 402 with PAYMENT-REQUIRED header and x402Version 2 body, 2026-09-19'
    note: Payment is per request and is not an identity; the provider states raw agent identifiers are not retained.
request_headers:
- name: x-idempotency-key
  required: true
  on: ['POST /v1/research', 'POST /v1/agent/beta/query', 'POST /v1/agent/trial/query', 'POST /v1/agent/utility/inference', 'POST /v1/agent/utility/spend-router', 'POST /v1/agent/wisdom/provider-select']
  observed: 'omitting it on POST /v1/research -> 400 IDEMPOTENCY_KEY_REQUIRED'
- name: x-agent-id
  required: false
  on: ['POST /v1/agent/trial/query (declared)']
  note: Optional caller-supplied agent identifier; the CORS allow-list also names x-bcg-agent-id, x-bcg-client-version, x-bcg-telemetry-class and x-bcg-discovery-source, none of which the contract documents.
- name: x-bcg-admin-token
  required: false
  note: Appears only in the Access-Control-Allow-Headers list. An operator credential, never documented or issued; not a customer scheme.
- name: MCP-Protocol-Version
  required: true
  on: ['POST /mcp']
  value: '2026-07-28'
mcp:
  auth: none
  oauth_metadata: {oauth_authorization_server: 404, oauth_protected_resource: 404, openid_configuration: 404}
a2a:
  securitySchemes: {}
  securityRequirements: []

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/berrergate-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.