Coin Railz · Authentication Profile

Coinrailz Com Authentication

Authentication

Four schemes derived from the Agent Payment API OpenAPI and confirmed against the provider's live machine-readable auth document GET https://coinrailz.com/api/auth/capabilities (HTTP 200, saved verbatim alongside). The x402 services OpenAPI declares no securitySchemes at all; the overlay in overlays/ adds the two that apply. No OAuth2 / OIDC anywhere (well-known metadata 404), so scopes/ is deliberately absent.

Coin Railz secures its APIs with apiKey and http across 4 declared security schemes, as derived from its OpenAPI definitions.

CompanyPaymentsAgentsx402MicropaymentsCryptocurrencyDeFiBlockchainStablecoinsUSDCPrediction MarketsSatellite DataIoTTradingComplianceMCPA2A
Methods: apiKey, http Schemes: 4 OAuth flows: API key in: header

Security Schemes

apiKey apiKey
· in: header (X-API-KEY)
bearerApiKey http
scheme: bearer
x402 apiKey
· in: header (X-PAYMENT)
mpp http
scheme: payment

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/coinrailz-com-agent-payment-api-openapi.yml
summary:
  types:
  - apiKey
  - http
  api_key_in:
  - header
schemes:
- name: apiKey
  type: apiKey
  in: header
  parameter: X-API-KEY
  description: Prepaid credits API key (cr_live_...). Obtain via GET /api/m2m/credits/trial (free $5) or POST /api/m2m/credits/checkout/session
    (paid).
  sources:
  - openapi/coinrailz-com-agent-payment-api-openapi.yml
- name: bearerApiKey
  type: http
  scheme: bearer
  description: 'Same cr_live_ key as X-API-KEY, passed as Authorization: Bearer <key>.'
  sources:
  - openapi/coinrailz-com-agent-payment-api-openapi.yml
- name: x402
  type: apiKey
  in: header
  parameter: X-PAYMENT
  description: x402 protocol on-chain USDC payment. Base64url-encoded signed payment payload. See /.well-known/x402.json
    for facilitator details.
  sources:
  - openapi/coinrailz-com-agent-payment-api-openapi.yml
- name: mpp
  type: http
  scheme: payment
  description: 'MPP (Machine Payments Protocol) credential. Authorization: Payment <base64-credential>. See /.well-known/mpp.json.'
  sources:
  - openapi/coinrailz-com-agent-payment-api-openapi.yml
docs: https://coinrailz.com/api/auth/capabilities
docs_file: authentication/coinrailz-com-auth-capabilities.json
description: Four schemes derived from the Agent Payment API OpenAPI and confirmed against the provider's live machine-readable
  auth document GET https://coinrailz.com/api/auth/capabilities (HTTP 200, saved verbatim alongside). The x402 services
  OpenAPI declares no securitySchemes at all; the overlay in overlays/ adds the two that apply. No OAuth2 / OIDC
  anywhere (well-known metadata 404), so scopes/ is deliberately absent.
auth_modes_published:
- mode: api_key
  header: X-API-KEY
  alternative_header: 'Authorization: Bearer <key>'
  description: Prepaid credits — fastest path. Works with any HTTP client. No wallet required.
- mode: x402_onchain
  header: X-PAYMENT
  alternative_header: null
  description: On-chain USDC per-call payments using HTTP 402 protocol. No API key required.
key_prefix: cr_live_
obtain:
  free_trial: GET https://coinrailz.com/api/m2m/credits/trial ($5, 1 per IP per 7 days, key returned once)
  hosted_checkout: POST https://coinrailz.com/api/m2m/credits/checkout/session -> Stripe checkoutUrl + retrievalToken
  direct_card: POST https://coinrailz.com/api/m2m/credits/purchase {paymentMethodId, amountUsd, idempotencyKey}
  on_chain: answer the 402 challenge with X-PAYMENT (x402 v2, CDP facilitator)
  mpp: 'Authorization: Payment <credential> per /.well-known/mpp.json'
public_operations: 21

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/coinrailz-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.