ByKaranteli · Authentication Profile
Bykaranteli Authentication
Authentication
ByKaranteli declares 4 security scheme(s) across its OpenAPI definitions.
CryptocurrencyCrypto DerivativesMarket DataFunding RatesOpen InterestLiquidationsOptionsETF FlowsFinancial DataMCPx402Agents
Methods:
Schemes: 4
OAuth flows:
API key in:
Security Schemes
none
http
scheme: bearer
· in: header ()
payment
scheme: exact
· in: header ()
none
Source
Authentication Profile
generated: '2026-08-09'
method: searched
source: https://bykaranteli.com/developers
docs: https://bykaranteli.com/developers
also_searched:
- https://bykaranteli.com/api/v1/public/manifest
- https://bykaranteli.com/openapi.json
- https://mcp.bykaranteli.com
summary: >-
ByKaranteli runs three distinct access models on one host. The public read
surface (/api/public/*, /api/v1/public/*) takes no credential at all. A small
account surface (/api/v1/public/me, /api/v1/me/*) takes a Bearer API key owned
by a registered member. The paid agent surface (/api/x402/*) takes no account
and no key — it authenticates the CALL, not the caller, by settling a USDC
micropayment over the x402 protocol. The hosted MCP server at
mcp.bykaranteli.com answered an anonymous tools/list, confirming it is
unauthenticated.
schemes:
- id: none
type: none
applies_to:
- /api/public/*
- /api/v1/public/* (except /me)
- /api/liqmap/public
- /embed/*
- /feed.xml
description: >-
No authentication. CORS Access-Control-Allow-Origin is *, GET and OPTIONS
preflight are supported, responses are read-only and carry no PII.
evidence: 'developers page "Auth · None · All endpoints public / read-only"'
- id: bearer_api_key
type: http
scheme: bearer
in: header
header: Authorization
format: 'Authorization: Bearer <api key>'
alternatives:
- 'query parameter ?api_key= (for clients that cannot set headers, e.g. calendar feeds)'
- 'query parameter ?token='
applies_to:
- /api/v1/public/me
- /api/v1/me/*
requires: member account with public_profile_enabled
rate_limit: 60 req/min/key
description: >-
Member-scoped Bearer token. Same response shape as
/api/v1/public/profiles/[handle] but for the key owner.
evidence: >-
/api/v1/public/manifest -> conventions.auth: "Bearer token in Authorization
header, or ?api_key= / ?token= for clients that can't set headers."
- id: x402_payment
type: payment
protocol: x402
version: 2
in: header
request_header: X-PAYMENT
challenge_header: payment-required
challenge_status: 402
applies_to:
- /api/x402/* (13 paid endpoints; /api/x402 catalog itself is free)
assets: [USDC]
networks:
- id: 'solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp'
chain: Solana mainnet
asset_mint: EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
pay_to: 4JgPtoBWkQyG3QffVJC3bfgk7SCQrz9bx2SAEUTSVqzK
fee_payer: GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb
- id: 'eip155:8453'
chain: Base mainnet
asset_contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'
pay_to: '0x0db4c96d8b14f431f3bb8ce1a33f07d2c696a62c'
scheme: exact
max_timeout_seconds: 300
description: >-
Call the endpoint with no payment and it answers HTTP 402 with a base64
`payment-required` header carrying x402 v2 payment requirements — resource
URL, service name, tags, accepted networks/assets/amounts, and a `bazaar`
extension whose JSON Schema describes the call's input and output shape.
An x402 client pays and retries automatically. Price is per SUCCESSFUL
response; a failed request settles nothing. No signup on either side.
verbatim_challenge: examples/bykaranteli-x402-payment-required.json
evidence:
url: https://bykaranteli.com/api/x402/flow-vpin
http_status: 402
fetched: '2026-08-09'
- id: mcp_anonymous
type: none
applies_to:
- https://mcp.bykaranteli.com (Streamable HTTP)
description: >-
Hosted MCP server requires no key. No OAuth discovery documents are
published (/.well-known/oauth-authorization-server and
/oauth-protected-resource both 404), consistent with an unauthenticated
read-only server.
evidence:
url: https://mcp.bykaranteli.com
method: 'POST tools/list'
http_status: 200
result: 20 tools returned anonymously
oauth2: false
openid_connect: false
mutual_tls: false
scopes: none
notes:
- >-
There is no OAuth surface, so no scopes/ artifact is emitted — the key-auth
member surface carries the model instead.
- >-
The published OpenAPI (/openapi.json) declares no components.securitySchemes;
it marks the free catalog operation `security: []` and leaves the paid
operations implicitly gated by the 402 flow. That is the one authentication
gap worth raising with the provider — an `x-payment-info` extension is
present per operation, but a formal securityScheme is not.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bykaranteli-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.