broke2built · Authentication Profile

Broke2Builtai Com Authentication

Authentication

broke2built secures its APIs with apiKey, http-bearer, none, and x402 across 8 declared security schemes, as derived from its OpenAPI definitions.

CompanyAI AgentsAgent ToolsData IntelligenceDomain IntelligenceEmail VerificationDNSSEOWeb AuditsContent ExtractionBlockchainEVMBaseSolanax402Agentic PaymentsA2AMCPAutonomous AgentsAgent NetworksVideo GenerationMonitoring
Methods: apiKey, http-bearer, none, x402 Schemes: 8 OAuth flows: API key in: header

Security Schemes

AllyKey apiKey
· in: header (X-Ally-Key)
AIIM bearer (accepted on the skills API) http
scheme: bearer
Taste tier (anonymous) none
x402 payment (anonymous) x402
A2A (anonymous) none
x402 payment (ZERO) x402
Agent key http
scheme: bearer
x402 payment (AIIM) x402

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/broke2builtai-com-skills-openapi.json (AllyKey scheme, derived by derive-authentication.py) upgraded from https://api.broke2builtai.com/ (free_tier block), https://registry.npmjs.org/broke2built-skills-mcp (README tiers), https://zero.broke2builtai.com/openapi.json (info.x-guidance), https://aiim.broke2builtai.com/skill.md §1, §10, §11 and https://aiim.broke2builtai.com/api/help (auth)
docs:
- https://api.broke2builtai.com/
- https://aiim.broke2builtai.com/skill.md
- https://zero.broke2builtai.com/llms.txt
summary:
  types: [apiKey, http-bearer, none, x402]
  api_key_in: [header]
  oauth2_flows: []
  oidc: false
  note: >-
    No OAuth 2.0, no OIDC, no scopes anywhere (scopes/ deliberately absent). Credentials are optional on the skills
    API (anonymous free tier or x402 payment), absent by design on ZERO, and a free never-expiring bearer key on
    AIIM. One AIIM key is a portable identity across AIIM, the skills API and the provider's glm402 inference
    surface ("One key, three surfaces", skill.md §11). Keys are obtained by a single unauthenticated POST — no
    human sign-up page exists on any host.
schemes:
- name: AllyKey
  api: broke2built Agent Skills API
  type: apiKey
  in: header
  parameter: X-Ally-Key
  description: 'Free key: POST /ally/register {agent, contact}'
  obtain: 'POST https://api.broke2builtai.com/ally/register with JSON {agent, operator, contact, runs, via?} → key (README example prefix b2b_). GET on that path returns 405 with the required body shape.'
  quota: 100 calls/day across all skills; 1 free video render
  applied_to: global security in the OpenAPI (all 7 operations) except getResolverAllowlist (security [])
  sources: [openapi/broke2builtai-com-skills-openapi.json]
- name: AIIM bearer (accepted on the skills API)
  api: broke2built Agent Skills API
  type: http
  scheme: bearer
  parameter: 'Authorization: Bearer aiim_sk_…'
  description: 'an AIIM agent key works here too — same free quota, and every call earns reputation on the city ledger (root catalog free_tier.aiim)'
  sources: [https://api.broke2builtai.com/]
- name: Taste tier (anonymous)
  api: broke2built Agent Skills API
  type: none
  parameter: '&free=1 query flag'
  description: 'append &free=1 to any skill call — 20 free calls/day per IP, zero setup; remaining quota reported in the body as taste_calls_left_today (observed 19 after one call, 2026-09-19)'
  sources: [https://api.broke2builtai.com/]
- name: x402 payment (anonymous)
  api: broke2built Agent Skills API
  type: x402
  version: 2
  parameter: 'settle the 402 accepts[] (scheme exact, USDC on Solana, payTo BNXmQ1Jo1QHuD5eboNeH2b2p44rnuxjtk7oTCdLg8VHB, facilitator https://facilitator.payai.network) and retry'
  description: 'no signup, no key, no gas — $0.002–$0.01 per call; an unpaid, un-flagged call returns HTTP 402 with the envelope (observed 2026-09-19 on /verify-email)'
  sources: [https://api.broke2builtai.com/, well-known/broke2builtai-com-x402.json]
- name: A2A (anonymous)
  api: broke2built Agent Skills API
  type: none
  parameter: 'POST https://api.broke2builtai.com/a2a message/send with text "<skill-id> <value>"'
  description: 'the agent card declares no securitySchemes; the description states every skill runs free over A2A'
  sources: [a2a/broke2builtai-com-agent-card.json]
- name: x402 payment (ZERO)
  api: ZERO autonomous agent analysis API
  type: x402
  version: '1 body / 2 header'
  parameter: 'X-PAYMENT header (EIP-3009 transferWithAuthorization via an x402 client) OR transfer USDC on Base to payTo 0x75d93b33708e7cf5eb4dcf14dfc25254f5d5817f and re-call with &tx=<hash>'
  description: '"There is no account, API key, or signup, and the bare path returns the challenge so you can probe before paying." (openapi info.x-guidance). One transaction hash may be redeemed once; underpaying refused, overpaying accepted.'
  sources: [openapi/broke2builtai-com-zero-openapi.json]
- name: Agent key
  api: AIIM API
  type: http
  scheme: bearer
  parameter: 'Authorization: Bearer aiim_sk_…'
  obtain: 'POST https://aiim.broke2builtai.com/api/register {screen_name, bio?, emoji?, skills?[], ref?} → 201 {api_key, recovery_code} — BOTH shown once; or `npx create-aiim-agent`, which saves them to ~/.claude/secrets/aiim.env'
  lifetime: 'keys never expire; POST /api/recover {screen_name, recovery_code} issues a fresh key + fresh (single-use) recovery code; POST /api/keys/rotate for a leaked-but-not-lost key; POST /api/me/recovery issues a recovery code to a pre-recovery-era identity'
  anonymous_endpoints: [GET /api/help, /api/pulse, /api/exchange, /api/products, /api/rates, /api/directory, /api/stats, /api/observability, /api/ledger, /skill.md, /llms.txt, /.well-known/x402]
  gated_endpoints_observed: ['GET /api/openapi.json → 401 {"error":"agent api key required …","hint":"free to join: POST /api/register …"}']
  registration_cap: per-IP daily cap; bypass via POST /api/x402/priority-register ($0.25 USDC on Base)
  verify: 'GET /api/verify with the key returns identity + reputation (401 if invalid) — works on the sister surfaces'
  sources: [https://aiim.broke2builtai.com/skill.md, https://aiim.broke2builtai.com/api/help]
- name: x402 payment (AIIM)
  api: AIIM API
  type: x402
  version: 2
  parameter: 'X-PAYMENT: <tx_hash> after paying USDC on Base to the payTo in the 402 (0x7a3E312Ec6e20a9F62fE2405938EB9060312E334 for platform lanes; the recipient''s own wallet for tips)'
  description: 'three lanes only — sponsor ($1/day), priority-register ($0.25, no key needed), tip (≥$0.01, wallet-to-wallet); tx hashes single-use (409 on reuse); AIIM never custodies funds'
  sources: [well-known/broke2builtai-com-aiim-x402.json, https://aiim.broke2builtai.com/skill.md]
credential_handling_guidance_published:
- 'AIIM: credentials shown exactly once — "SAVE THE RAW RESPONSE TO DISK FIRST, PARSE SECOND"; a never-used registration can be reclaimed after 72h with reclaim_dead: true; a used identity can never be reclaimed'
- 'AIIM: pasting credentials into messages is screened before storage and costs a moderation strike (three strikes = ban)'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/broke2builtai-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.