ByKaranteli · Authentication Profile

Bykaranteli Authentication

Authentication

ByKaranteli declares 4 security scheme(s) across its OpenAPI definitions.

CryptocurrencyCrypto DerivativesMarket DataFunding RatesOpen InterestLiquidationsOptionsETF FlowsFinancial DataMCPx402Agents
Methods: Schemes: 4 OAuth flows: API key in:

Security Schemes

none
http
scheme: bearer · in: header ()
payment
scheme: exact · in: header ()
none

Source

Authentication Profile

Raw ↑
generated: '2026-08-09'
method: searched
source: https://bykaranteli.com/developers
docs: https://bykaranteli.com/developers
also_searched:
  - https://bykaranteli.com/api/v1/public/manifest
  - https://bykaranteli.com/openapi.json
  - https://mcp.bykaranteli.com

summary: >-
  ByKaranteli runs three distinct access models on one host. The public read
  surface (/api/public/*, /api/v1/public/*) takes no credential at all. A small
  account surface (/api/v1/public/me, /api/v1/me/*) takes a Bearer API key owned
  by a registered member. The paid agent surface (/api/x402/*) takes no account
  and no key — it authenticates the CALL, not the caller, by settling a USDC
  micropayment over the x402 protocol. The hosted MCP server at
  mcp.bykaranteli.com answered an anonymous tools/list, confirming it is
  unauthenticated.

schemes:
  - id: none
    type: none
    applies_to:
      - /api/public/*
      - /api/v1/public/* (except /me)
      - /api/liqmap/public
      - /embed/*
      - /feed.xml
    description: >-
      No authentication. CORS Access-Control-Allow-Origin is *, GET and OPTIONS
      preflight are supported, responses are read-only and carry no PII.
    evidence: 'developers page "Auth · None · All endpoints public / read-only"'

  - id: bearer_api_key
    type: http
    scheme: bearer
    in: header
    header: Authorization
    format: 'Authorization: Bearer <api key>'
    alternatives:
      - 'query parameter ?api_key= (for clients that cannot set headers, e.g. calendar feeds)'
      - 'query parameter ?token='
    applies_to:
      - /api/v1/public/me
      - /api/v1/me/*
    requires: member account with public_profile_enabled
    rate_limit: 60 req/min/key
    description: >-
      Member-scoped Bearer token. Same response shape as
      /api/v1/public/profiles/[handle] but for the key owner.
    evidence: >-
      /api/v1/public/manifest -> conventions.auth: "Bearer token in Authorization
      header, or ?api_key= / ?token= for clients that can't set headers."

  - id: x402_payment
    type: payment
    protocol: x402
    version: 2
    in: header
    request_header: X-PAYMENT
    challenge_header: payment-required
    challenge_status: 402
    applies_to:
      - /api/x402/* (13 paid endpoints; /api/x402 catalog itself is free)
    assets: [USDC]
    networks:
      - id: 'solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp'
        chain: Solana mainnet
        asset_mint: EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
        pay_to: 4JgPtoBWkQyG3QffVJC3bfgk7SCQrz9bx2SAEUTSVqzK
        fee_payer: GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb
      - id: 'eip155:8453'
        chain: Base mainnet
        asset_contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'
        pay_to: '0x0db4c96d8b14f431f3bb8ce1a33f07d2c696a62c'
    scheme: exact
    max_timeout_seconds: 300
    description: >-
      Call the endpoint with no payment and it answers HTTP 402 with a base64
      `payment-required` header carrying x402 v2 payment requirements — resource
      URL, service name, tags, accepted networks/assets/amounts, and a `bazaar`
      extension whose JSON Schema describes the call's input and output shape.
      An x402 client pays and retries automatically. Price is per SUCCESSFUL
      response; a failed request settles nothing. No signup on either side.
    verbatim_challenge: examples/bykaranteli-x402-payment-required.json
    evidence:
      url: https://bykaranteli.com/api/x402/flow-vpin
      http_status: 402
      fetched: '2026-08-09'

  - id: mcp_anonymous
    type: none
    applies_to:
      - https://mcp.bykaranteli.com (Streamable HTTP)
    description: >-
      Hosted MCP server requires no key. No OAuth discovery documents are
      published (/.well-known/oauth-authorization-server and
      /oauth-protected-resource both 404), consistent with an unauthenticated
      read-only server.
    evidence:
      url: https://mcp.bykaranteli.com
      method: 'POST tools/list'
      http_status: 200
      result: 20 tools returned anonymously

oauth2: false
openid_connect: false
mutual_tls: false
scopes: none
notes:
  - >-
    There is no OAuth surface, so no scopes/ artifact is emitted — the key-auth
    member surface carries the model instead.
  - >-
    The published OpenAPI (/openapi.json) declares no components.securitySchemes;
    it marks the free catalog operation `security: []` and leaves the paid
    operations implicitly gated by the 402 flow. That is the one authentication
    gap worth raising with the provider — an `x-payment-info` extension is
    present per operation, but a formal securityScheme is not.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bykaranteli-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.