ChainAware.ai · Authentication Profile

Chainaware Ai Authentication

Authentication

ChainAware.ai secures its APIs with apiKey across 6 declared security schemes, as derived from its OpenAPI definitions.

BlockchainWeb3DeFiFraud PreventionAMLComplianceCredit ScoringRisk ScoringSmart Contract SecurityAgent TrustMCPA2Ax402AgentsAgent-NativeEstonia
Methods: apiKey Schemes: 6 OAuth flows: API key in: header, query (MCP SSE URL only), tool argument (MCP, in-band)

Security Schemes

ApiKeyAuth apiKey
· in: header (x-api-key)
apiKey (A2A card) apiKey
· in: header (x-api-key)
x402Payment apiKey
· in: header (X-PAYMENT)
X-API-Key (MCP connection header) apiKey
· in: header (X-API-Key)
apiKey (MCP SSE query parameter) apiKey
· in: query (apiKey)
apiKey (MCP tool argument) apiKey
· in: tool-argument (apiKey)

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/chainaware-ai-enterprise-api-openapi.yml
docs: https://chainaware.ai/learn/api/index.html
additional_docs:
- https://chainaware.ai/learn/prediction-mcp/setup.html
- https://api.chainaware.ai/.well-known/agent-card.json
- https://github.com/ChainAware/behavioral-prediction-mcp
summary:
  types:
  - apiKey
  api_key_in:
  - header
  - query (MCP SSE URL only)
  - tool argument (MCP, in-band)
  payment_credential:
  - x402 (X-PAYMENT header, USDC on Base)
  oauth2: false
  openid_connect: false
  mutual_tls: false
  key_issuance: https://chainaware.ai/profile (Business or Enterprise subscription; "custom volume pricing" by contact)
  anonymous_access: 'discovery on every surface (agent card, /api/capabilities, MCP initialize + tools/list); eight MCP tools callable with no key; website tools free'
schemes:
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter: x-api-key
  surface: REST Enterprise API (https://enterprise.api.chainaware.ai) and the x402 REST twin at https://api.chainaware.ai/api/*
  description: Your ChainAware API key. Available at chainaware.ai/profile. Keep it private — do not expose it in client-side code or public repositories.
  failure: 'Docs: 401 Unauthorized when missing or invalid. Observed: a request with NO key to enterprise.api.chainaware.ai is answered 403 {"message":"Forbidden"} by the AWS API Gateway edge before the application sees it.'
  sources:
  - openapi/chainaware-ai-enterprise-api-openapi.yml
  - https://chainaware.ai/learn/api/index.html
- name: apiKey (A2A card)
  type: apiKey
  in: header
  parameter: x-api-key
  surface: A2A skills at https://api.chainaware.ai/api/a2a/
  description: 'API key for authenticated access. Obtain your key at https://chainaware.ai/pricing.'
  sources:
  - a2a/chainaware-ai-agent-card.json
- name: x402Payment
  type: apiKey
  in: header
  parameter: X-PAYMENT
  surface: A2A skills and https://api.chainaware.ai/api/* (and MCP tool calls when apiKey is omitted, per the README)
  description: 'x402 micropayment header. See https://x402.org for payment construction details. An unpaid request returns HTTP 402 with a base64 `payment-required` header (x402 v2 PaymentRequirements: exact scheme, eip155:8453, 150000 units of USDC 0x8335…2913 = $0.15, payTo 0x9e60…CeA08, 300 s validity).'
  evidence: a2a/chainaware-ai-x402-payment-required.json
  sources:
  - a2a/chainaware-ai-agent-card.json
  - https://api.chainaware.ai/api/capabilities
- name: X-API-Key (MCP connection header)
  type: apiKey
  in: header
  parameter: X-API-Key
  surface: MCP SSE connection to https://prediction.mcp.chainaware.ai/sse (Claude Code `--header`, Cursor `headers`, SDK requestInit)
  description: Documented connection-level key; the connection, initialize and tools/list nevertheless succeed without it.
  sources:
  - https://chainaware.ai/learn/prediction-mcp/setup.html
  - mcp/chainaware-ai-mcp.yml
- name: apiKey (MCP SSE query parameter)
  type: apiKey
  in: query
  parameter: apiKey
  surface: 'MCP SSE URL for ChatGPT Connectors and Claude Web/Desktop Integrations: https://prediction.mcp.chainaware.ai/sse?apiKey=YOUR_API_KEY'
  description: The setup guide documents the key in the URL for clients that cannot set headers. A key in a URL is logged by intermediaries; the guide does not warn about this.
  sources:
  - https://chainaware.ai/learn/prediction-mcp/setup.html
- name: apiKey (MCP tool argument)
  type: apiKey
  in: tool-argument
  parameter: apiKey
  surface: 'Six MCP tools: predictive_fraud, predictive_fraud_batch, predictive_behaviour, predictive_behaviour_batch, predictive_rug_pull, credit_score (required inputSchema property)'
  description: 'The credential travels INSIDE the JSON-RPC tool call, visible to the model. SKILL.md: "Passed as the apiKey parameter in every tool call ... Never logged or included in output. Sourced exclusively from the CHAINAWARE_API_KEY environment variable — never hardcoded." Omit it to pay with x402 instead (README). Failure: 403 "invalid or missing apiKey" as tool-result text.'
  sources:
  - mcp/chainaware-ai-mcp-tools.json
  - skills/chainaware-ai-SKILL.md
note: >-
  One credential (a ChainAware API key) presented five ways across three surfaces, plus x402 payment as a
  credential-free alternative on the agent surfaces. No OAuth 2.0, OIDC, scopes or client registration exist,
  and no RFC 8414 / 9728 discovery document is served on any host (see well-known/). Keys are per account with
  no documented test/live prefix, rotation or expiry.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/chainaware-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.