Block Lottos · Authentication Profile
Blocklottos Com Authentication
Authentication
Block Lottos secures its APIs with none, http-bearer, and wallet-signature across 4 declared security schemes, as derived from its OpenAPI definitions.
CompanyLotteryBlockchainWeb3GamingCryptocurrencyAdvertisingAffiliate MarketingAI AgentsBasePolygonUSDCSmart ContractsA2A
Methods: none, http-bearer, wallet-signature
Schemes: 4
OAuth flows:
API key in:
Security Schemes
public none
managementToken http
scheme: bearer
· in: header (Authorization)
walletOwnershipChallenge wallet-signature
onChainSignature wallet-signature
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: 'openapi/blocklottos-com-openapi.yml (no securitySchemes; POST /api/lottery/agent-referral declares an optional
Authorization header parameter with pattern ^Bearer blm_[0-9a-f]{64}$), https://blocklottos.com/api-docs (#ads-overview
"No API key required", #lottery-overview "Authentication: None required, all read endpoints are public", #agent-referral
challenge/sign flow), /.well-known/ai-plugin.json auth.type none, /.well-known/agent.json trust.no_api_key_for_read_endpoints,
live CORS allow-headers 2026-09-19.'
docs: https://blocklottos.com/api-docs#agent-referral
summary:
types:
- none
- http-bearer
- wallet-signature
api_key_in: []
oauth2_flows: []
default: none - every read endpoint and every unsigned-transaction builder is public and key-less; access control
for money lives in the caller's wallet, not in the API.
schemes:
- name: public
type: none
applies_to: all GET operations, buildLotteryTicketTx, submitAd/activate quote and pay steps, getBaseAgentCapabilities,
prepareBaseAgentPurchase, confirmBaseTicketPurchase
rate_limited: per IP (see rate-limits/)
sources:
- openapi/blocklottos-com-openapi.yml
- https://blocklottos.com/api-docs
- name: managementToken
type: http
scheme: bearer
bearerFormat: blm_ + 64 hex chars
in: header
parameter: Authorization
applies_to: getOrCreateUnifiedAffiliateProfile only - payout-wallet changes and private balance/payout-history
reads
issuance: Returned ONCE when a new affiliate profile is created (or rotated) after a successful ownership proof;
"Store the one-time management_token securely".
declared_as: an optional header PARAMETER on the operation, not a securityScheme - the contract therefore reports
no security at all to tooling
sources:
- openapi/blocklottos-com-openapi.yml
- https://blocklottos.com/api-docs#agent-referral
- https://blocklottos.com/llms.txt
- name: walletOwnershipChallenge
type: wallet-signature
flow:
- POST /api/lottery/agent-referral {"action":"challenge","primary_chain":"evm","connected_wallet":"0x..."}
- sign the exact returned message with the EVM identity wallet (EIP-191 personal_sign, 65-byte hex); the spec
also accepts a Solana Ed25519 64-byte hex signature
- resubmit with challenge_id (48 hex) + signature
applies_to: affiliate enrollment and management-token recovery
cost: 0 USDC, no on-chain transaction
sources:
- openapi/blocklottos-com-openapi.yml
- https://blocklottos.com/agents.txt
- name: onChainSignature
type: wallet-signature
note: 'Not API authentication, but the actual authorization for money: the API returns unsigned transactions and
the wallet owner signs/broadcasts with eth_sendTransaction; "The Block Lottos server never receives private
keys or seed phrases, never signs wallet transactions, and never broadcasts them." (llms.txt)'
identification_headers:
- name: X-BlockLottos-Agent
required: false
purpose: optional agent identifier used in the docs curl examples; also carried as agent_id in bodies
- name: X-BlockLottos-Intent
required: false
purpose: listed in Access-Control-Allow-Headers on the agent endpoints; undocumented
- name: Idempotency-Key
required: false
purpose: listed in Access-Control-Allow-Headers on agent-purchase and agent-referral; the documented mechanism
is the idempotency_key body field (see conventions/)
gaps:
- No securitySchemes block, so the Bearer requirement is invisible to generated clients.
- No scopes, no OAuth, no API-key issuance - nothing to record in scopes/.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/blocklottos-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.