Block Lottos · Authentication Profile

Blocklottos Com Authentication

Authentication

Block Lottos secures its APIs with none, http-bearer, and wallet-signature across 4 declared security schemes, as derived from its OpenAPI definitions.

CompanyLotteryBlockchainWeb3GamingCryptocurrencyAdvertisingAffiliate MarketingAI AgentsBasePolygonUSDCSmart ContractsA2A
Methods: none, http-bearer, wallet-signature Schemes: 4 OAuth flows: API key in:

Security Schemes

public none
managementToken http
scheme: bearer · in: header (Authorization)
walletOwnershipChallenge wallet-signature
onChainSignature wallet-signature

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: 'openapi/blocklottos-com-openapi.yml (no securitySchemes; POST /api/lottery/agent-referral declares an optional
  Authorization header parameter with pattern ^Bearer blm_[0-9a-f]{64}$), https://blocklottos.com/api-docs (#ads-overview
  "No API key required", #lottery-overview "Authentication: None required, all read endpoints are public", #agent-referral
  challenge/sign flow), /.well-known/ai-plugin.json auth.type none, /.well-known/agent.json trust.no_api_key_for_read_endpoints,
  live CORS allow-headers 2026-09-19.'
docs: https://blocklottos.com/api-docs#agent-referral
summary:
  types:
  - none
  - http-bearer
  - wallet-signature
  api_key_in: []
  oauth2_flows: []
  default: none - every read endpoint and every unsigned-transaction builder is public and key-less; access control
    for money lives in the caller's wallet, not in the API.
schemes:
- name: public
  type: none
  applies_to: all GET operations, buildLotteryTicketTx, submitAd/activate quote and pay steps, getBaseAgentCapabilities,
    prepareBaseAgentPurchase, confirmBaseTicketPurchase
  rate_limited: per IP (see rate-limits/)
  sources:
  - openapi/blocklottos-com-openapi.yml
  - https://blocklottos.com/api-docs
- name: managementToken
  type: http
  scheme: bearer
  bearerFormat: blm_ + 64 hex chars
  in: header
  parameter: Authorization
  applies_to: getOrCreateUnifiedAffiliateProfile only - payout-wallet changes and private balance/payout-history
    reads
  issuance: Returned ONCE when a new affiliate profile is created (or rotated) after a successful ownership proof;
    "Store the one-time management_token securely".
  declared_as: an optional header PARAMETER on the operation, not a securityScheme - the contract therefore reports
    no security at all to tooling
  sources:
  - openapi/blocklottos-com-openapi.yml
  - https://blocklottos.com/api-docs#agent-referral
  - https://blocklottos.com/llms.txt
- name: walletOwnershipChallenge
  type: wallet-signature
  flow:
  - POST /api/lottery/agent-referral {"action":"challenge","primary_chain":"evm","connected_wallet":"0x..."}
  - sign the exact returned message with the EVM identity wallet (EIP-191 personal_sign, 65-byte hex); the spec
    also accepts a Solana Ed25519 64-byte hex signature
  - resubmit with challenge_id (48 hex) + signature
  applies_to: affiliate enrollment and management-token recovery
  cost: 0 USDC, no on-chain transaction
  sources:
  - openapi/blocklottos-com-openapi.yml
  - https://blocklottos.com/agents.txt
- name: onChainSignature
  type: wallet-signature
  note: 'Not API authentication, but the actual authorization for money: the API returns unsigned transactions and
    the wallet owner signs/broadcasts with eth_sendTransaction; "The Block Lottos server never receives private
    keys or seed phrases, never signs wallet transactions, and never broadcasts them." (llms.txt)'
identification_headers:
- name: X-BlockLottos-Agent
  required: false
  purpose: optional agent identifier used in the docs curl examples; also carried as agent_id in bodies
- name: X-BlockLottos-Intent
  required: false
  purpose: listed in Access-Control-Allow-Headers on the agent endpoints; undocumented
- name: Idempotency-Key
  required: false
  purpose: listed in Access-Control-Allow-Headers on agent-purchase and agent-referral; the documented mechanism
    is the idempotency_key body field (see conventions/)
gaps:
- No securitySchemes block, so the Bearer requirement is invisible to generated clients.
- No scopes, no OAuth, no API-key issuance - nothing to record in scopes/.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/blocklottos-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.