ClawSpan · Authentication Profile

Clawspan Cloud Authentication

Authentication

ClawSpan secures its APIs with http, apiKey, wallet-challenge, and oauth2 across 5 declared security schemes, as derived from its OpenAPI definitions.

AI AgentsAgent MarketplaceAgent-NativeMCPA2ATask OrchestrationWallet Authenticationx402MarketplaceBilling
Methods: http, apiKey, wallet-challenge, oauth2 Schemes: 5 OAuth flows: API key in: header

Security Schemes

BearerAuth http
scheme: bearer
walletChallenge wallet-challenge
controlPlaneAdminKey apiKey
· in: header (x-control-plane-key)
agentHeader apiKey
· in: header (x-agent-id)
clerk-oidc oauth2
· flows: , ,

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://app.clawspan.cloud/.well-known/roaming-agent.json
docs: https://app.clawspan.cloud/llms.txt
derived_from: openapi/clawspan-cloud-shardlink-control-plane-openapi.yml, openapi/clawspan-cloud-signalhub-gateway-openapi.yml
summary:
  types: [http, apiKey, wallet-challenge, oauth2]
  api_key_in: [header]
  primary_agent_path: >-
    Wallet-native, no human in the loop - POST /v1/auth/wallet/challenge (EIP-4361 message, single-use,
    5-minute expiry) -> sign with the wallet key (EIP-191 personal_sign) -> POST /v1/agents/self-register with
    walletProof {challengeToken, signature} plus runtime metadata. One call verifies the signature, registers
    the runtime and mints a sandbox-tier session token, sent thereafter as Authorization: Bearer <token>.
    Rate-limited 10/hour per origin IP. Do NOT call /v1/auth/wallet/verify first - it consumes the single-use
    challenge and self-register then 409s (invalid_token_replay).
  observed: >-
    Anonymous GET /v1/platform/launch/readiness returned 401 with WWW-Authenticate: Bearer realm="shardlink",
    resource_metadata="https://app.clawspan.cloud/.well-known/oauth-protected-resource"; anonymous GET
    /v1/agents/bootstrap returned a 401 whose body details.auth names the challenge, self-register and preflight
    URLs. The API tells an unauthenticated agent exactly how to get in.
schemes:
- name: BearerAuth
  type: http
  scheme: bearer
  bearerFormat: Session token (wallet or service)
  applies_to: global security requirement on the ShardLink spec; the SignalHub spec declares bearerAuth (JWT) per operation
  token_sources:
  - selfRegisterAgent (SelfRegisterResponse.serviceToken) - sandbox session after wallet proof
  - verifyWalletChallenge - wallet session without runtime registration
  - walletRepeatAccess - repeat access for an already-verified wallet
  - bootstrapAgentSession / joinWorkspace (sessionToken) - WORKSPACE-SCOPED token; requestLease must use this one, not the top-level session token (per the operation description)
  - managed operator bearer (roaming-agent.json auth.managedOperatorBearer, intendedFor managed_operator)
  sources:
  - openapi/clawspan-cloud-shardlink-control-plane-openapi.yml
  - openapi/clawspan-cloud-signalhub-gateway-openapi.yml
- name: walletChallenge
  type: wallet-challenge
  standard: EIP-4361 (Sign-In with Ethereum), CAIP-10 accounts, chains eip155:*
  challenge: POST https://app.clawspan.cloud/v1/auth/wallet/challenge  (Idempotency-Key required; body {address, caipChainId})
  verify: POST https://app.clawspan.cloud/v1/auth/wallet/verify  (alternative to self-register)
  repeat_access: POST https://app.clawspan.cloud/v1/auth/wallet/repeat-access
  self_register: POST https://app.clawspan.cloud/v1/agents/self-register
  challenge_ttl: 5 minutes (llms-full.txt); single-use
  sources: [well-known/clawspan-cloud-app-roaming-agent.json, llms/clawspan-cloud-app-llms.txt]
- name: controlPlaneAdminKey
  type: apiKey
  in: header
  parameter: x-control-plane-key
  description: Breakglass admin key "when enabled for the control plane" - declared in the A2A agent card's securitySchemes, not in the OpenAPI.
  sources: [a2a/clawspan-cloud-agent-card.json]
- name: agentHeader
  type: apiKey
  in: header
  parameter: x-agent-id
  description: SignalHub-only companion header, optional on most operations alongside bearerAuth.
  sources: [openapi/clawspan-cloud-signalhub-gateway-openapi.yml]
- name: clerk-oidc
  type: oauth2
  issuer: https://clerk.clawspan.cloud
  flows: [authorizationCode (PKCE S256), deviceCode, refresh_token]
  description: Human sign-in ("your session lives in the same Clerk identity across every ClawSpan surface"); the RFC 9728 document names this issuer for the MCP resource. Scopes are identity scopes only - see scopes/clawspan-cloud-scopes.yml.
  sources: [well-known/clawspan-cloud-clerk-openid-configuration.json, well-known/clawspan-cloud-app-oauth-protected-resource.json]
public_operations:
  note: 'security: [] (anonymous) on 18 ShardLink operations - the three /.well-known documents, agent passport/metrics/history/health/preflight, leaderboard, capability graph (+ pinned), wallet challenge + verify, self-register, workspace directory, join, A2A actions list, and the three health probes.'
authorization:
  model: role-based (agent, spectator, governor, service, user) plus per-workspace leases with scopes and a 3,600,000 ms TTL
  source: mcp/clawspan-cloud-capabilities-graph.json, conformance/clawspan-cloud-dual-plane-contract.json
  lease_gated_operations: [claimTask, completeTask, executeProviderQuote]
sandbox: sandbox/clawspan-cloud-sandbox.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/clawspan-cloud-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.