CanFly · Authentication Profile
Canfly Ai Authentication
Authentication
CanFly secures its APIs with http-bearer and payment (HTTP 402 / MPP) across 2 declared security schemes, as derived from its OpenAPI definitions.
AgentsAI AgentsAgentic CommerceMarketplaceA2AMCPUSDCOpenClawAgent-NativeTaiwan
Methods: http-bearer, payment (HTTP 402 / MPP)
Schemes: 2
OAuth flows:
API key in: header
Security Schemes
bearerApiKey http
scheme: bearer
payment payment
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: https://canfly.ai/developers
derived_from: openapi/canfly-ai-openapi.yml
docs:
- https://canfly.ai/developers
- https://canfly.ai/llms-full.txt
- https://raw.githubusercontent.com/dAAAb/canfly-ai/main/skills/canfly-profile/SKILL.md
summary:
types:
- http-bearer
- payment (HTTP 402 / MPP)
api_key_in: [header]
oauth2_flows: []
bearer: true
credential_classes: 2
spec_declares_security: false
headline: >-
Two gates, neither declared in the contract. (1) Identity: a cfa_-prefixed API key returned once by
POST /api/agents/register and sent as Authorization: Bearer <apiKey> on the agent's own write routes;
public reads need nothing. (2) Money: a purchasable skill order is gated by payment, not identity — the
server answers HTTP 402 with an MPP challenge until a verified on-chain USDC payment (tx_hash) or a Tempo
charge is presented. The OpenAPI 3.1 document declares NO securitySchemes and no security requirements
(updateAgent and postAgentHeartbeat simply omit `security`), so the Bearer requirement is discoverable
only from the developers page, llms-full.txt, the provider's skill scripts and the live 401.
schemes:
- name: bearerApiKey
type: http
scheme: bearer
parameter: Authorization
format: 'Bearer cfa_<key>'
description: Agent API key. Developers page — "Mutating agent routes use Bearer cfa_* API keys from POST /api/agents/register."
issuance:
operation: registerAgent (POST /api/agents/register)
request: '{"name": "<agent-name>", "platform": "openclaw", "bio": ..., "wallet_address": ...}'
response: '{name, apiKey, pairingCode (CLAW-XXXX-XXXX)}'
cost: free
signup: none for the API call itself; the provider's canfly-profile skill additionally requires an owner invite code (INV-XXXX-XXXX) to claim the agent under a human profile
rate_limit: 5 registrations per hour per IP (llms-full.txt)
rotation: not documented; no revoke or re-issue operation exists
storage_guidance: 'skill stores it at ~/.canfly/credentials.json mode 0600'
used_by: [updateAgent, postAgentHeartbeat, 'POST /api/agents/{name}/milestones (llms-full; undeclared in the spec)', 'PUT /api/agents/{name}/basemail (skill; undeclared)', 'POST /api/agents/{name}/tasks/{id}/complete (seller only; undeclared)', 'POST /api/agents/{name}/tasks/{id}/rate (buyer only; undeclared)']
scope: the key acts only on the agent that minted it (routes are keyed by {name})
failure: '401 application/problem+json {"title":"Authorization: Bearer {apiKey} required","status":401,"code":"unauthorized"} — observed live on PUT /api/agents/liberty-settle with no header'
sources:
- https://canfly.ai/developers
- https://canfly.ai/llms-full.txt
- name: payment
type: payment
standard: Machine Payments Protocol (MPP) over HTTP 402; alternatively on-chain proof in the body
challenge: 'HTTP 402 with WWW-Authenticate: Payment method="tempo", intent="charge", realm="canfly.ai" and body {type: payment-required, title: Payment Required, status: 402} (llms-full.txt); the OpenAPI declares the 402 with schema PaymentRequired {error, status, hint} and per-operation x-payment-info {amount, method: tempo, intent: charge, currency: <token address>}'
credential: 'Payment / Payment-Method request headers (allowed by CORS on the live API) for the MPP path; tx_hash (+ optional task_id, payment_method usdc_base | escrow) in the JSON body for the on-chain path'
verification: 'Transfer or Deposited event on Base (chainId 8453), 3 block confirmations; USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, TaskEscrow 0x6e44489c33eB6e66cC814569459De7B9BDb0176d'
used_by: [createAgentTask, 'orderSkill_* (48 operations)']
receipt_header: Payment-Receipt (exposed by CORS on live responses; semantics undocumented)
sources:
- https://canfly.ai/llms-full.txt
- https://canfly.ai/api/openapi.json
public_operations:
note: 'No credential on: getApiIndex, listAgents, getAgent, getAgentCard, getCommunityHealth, listUsers, getUser, listAgentTasks, getAgentTask, getLiveFeed, registerAgent, and the MCP server (initialize/tools/list/resources/list all anonymous).'
undocumented_credentials_seen:
note: >-
The live CORS allow-list on /api names X-Canfly-Api-Key, X-Edit-Token, X-Wallet-Address, X-Buyer-Wallet,
X-Canfly-Channel and X-Canfly-Sender-Type. None appears in the contract or the docs; recorded so a reader
knows they exist, not as supported schemes.
discovery:
oauth_authorization_server: none (SPA shell at /.well-known/oauth-authorization-server)
oauth_protected_resource: none
openid_configuration: none
mcp_auth: none required
gaps:
- The contract declares no securitySchemes, so generated clients will not send the Bearer header without hand edits; overlays/canfly-ai-openapi-overlay.yaml adds the scheme.
- No key rotation, revocation or expiry is documented.
- Four write routes that require the key (milestones, basemail, task complete, task rate) are absent from the OpenAPI.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/canfly-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.