CONNSKILL Growth Services has no accounts and no API keys. Access is gated three ways: free routes are open; paid routes are gated by x402 payment (an unpaid request answers 402 with the exact price, and the same request is repeated with a PAYMENT-SIGNATURE header carrying an EIP-3009 USDC authorization on Base); and the private support / redelivery / manual-purchase routes require a Sign-In-With-X wallet proof — a one-use, five-minute EIP-191 signature over a server-issued challenge bound to the method, path and canonical JSON body. The MCP and A2A surfaces inherit the same model: the hosted MCP server forwards payment headers supplied by the caller and the A2A card declares no securitySchemes.
CONNSKILL secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.
generated: '2026-09-19'
method: searched
source: >-
openapi/connskill-com-openapi.yml (components.securitySchemes.signInWithX; info.x-trust.auth; security on 5 support
operations; 41 operations with x-payment-info and 402 responses); https://agent.connskill.com/v1/support/policy
(authentication block: chainId eip155:8453, type eip191, supportedWallets EOA, lifetimeSeconds 300, oneUse true,
challengeUrl /v1/support/challenge, messageBinding); https://agent.connskill.com/llms.txt ("How one call works");
https://agent.connskill.com/.well-known/agent-card.json (securitySchemes {} / security []);
https://agent.connskill.com/.well-known/ai-plugin.json (auth.type none); npm README (X402_WALLET_KEY).
docs: https://agent.connskill.com/llms.txt
description: >-
CONNSKILL Growth Services has no accounts and no API keys. Access is gated three ways: free routes are open;
paid routes are gated by x402 payment (an unpaid request answers 402 with the exact price, and the same request
is repeated with a PAYMENT-SIGNATURE header carrying an EIP-3009 USDC authorization on Base); and the private
support / redelivery / manual-purchase routes require a Sign-In-With-X wallet proof — a one-use, five-minute
EIP-191 signature over a server-issued challenge bound to the method, path and canonical JSON body. The MCP and
A2A surfaces inherit the same model: the hosted MCP server forwards payment headers supplied by the caller and
the A2A card declares no securitySchemes.
verbatim: >-
No account or API key. Manual first purchases and private redelivery require a free Sign-In-With-X wallet proof
from POST /v1/payments/challenge.
summary:
types: [apiKey]
api_key_in: [header]
accounts: false
api_keys: false
oauth2: false
oidc: false
payment_gated: true
free_operations: 47
paid_operations: 41
wallet_proof_operations: 5
schemes:
- name: signInWithX
type: apiKey
in: header
parameter: Sign-In-With-X
description: >-
Base64 JSON containing the exact challenge fields, checksummed address, chainId eip155:8453, type eip191 and
EIP-191 signature. Free authentication, not payment. One use, five minutes, bound to method, path and JSON body.
flow:
- POST /v1/support/challenge (support) or POST /v1/payments/challenge with purpose purchase | redelivery
(payments) — returns the exact message to sign and extensions.sign-in-with-x.info
- sign the message with the EOA wallet that paid (EIP-191)
- send the info fields plus address, chainId eip155:8453, type eip191 and signature as base64 JSON in the
Sign-In-With-X header on the target request
properties:
chain_id: eip155:8453
signature_type: eip191
supported_wallets: EOA
lifetime_seconds: 300
one_use: true
message_binding: [configured public origin, method, path, canonical JSON body]
ownership: Only the settled payer can access a purchase or its support case
applied_to: [supportTicketsList, supportTicketCreate, supportTicketGet, supportDiscountCheckout, supportDiscountClaim]
also_used_by: [paymentWalletChallenge (issues the proof), private redelivery on any paid route, manual X-Payment-Tx purchases]
failure: '401 Wallet proof missing, invalid, expired or reused; 429 Challenge rate limit; 503 Wallet authentication unavailable; no access granted'
docs: https://agent.connskill.com/v1/support/policy
sources: [openapi/connskill-com-openapi.yml, https://agent.connskill.com/v1/support/policy]
- name: x402Payment
type: payment
in: header
parameter: PAYMENT-SIGNATURE
legacy_parameter: X-Payment
protocol: x402 v2
description: >-
Not an authentication scheme in the OpenAPI components (it is declared per operation via x-payment-info and
402 responses) but the mechanism that actually gates 41 operations. An unpaid request answers HTTP 402 with
accepts[0].amount (micro-USDC), accepts[0].payTo, asset (USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913),
network eip155:8453 and maxTimeoutSeconds; the client signs an EIP-3009 authorization for exactly that amount
and repeats the same request with PAYMENT-SIGNATURE.
pay_to: '0x43B85AE58f0A2505c710Bc715d6f3EB16b1f63dE'
free_sample: 'x-free-sample: 1 — one free call per endpoint per UTC day on endpoints priced <= 0.15 USDC'
manual_purchase: >-
Where supported, transfer first, then POST /v1/payments/challenge with purpose purchase, the token payer address
and the exact target request (x-payment-tx header, complete JSON body, only ref query parameters) and send the
resulting Sign-In-With-X proof on the target request.
mcp: The hosted MCP server forwards PAYMENT-SIGNATURE / X-Payment from the outer HTTP request and does not sign; the npm server signs with X402_WALLET_KEY under X402_MAX_USD.
a2a: capabilities.extensions[0] = a2a-x402 v0.2 (required); paid skills return a payment-required task.
docs: https://agent.connskill.com/llms.txt
sources: [openapi/connskill-com-openapi.yml, https://agent.connskill.com/.well-known/x402, https://agent.connskill.com/llms.txt]
well_known:
oauth_authorization_server: 404 on agent.connskill.com and connskill.com
oauth_protected_resource: 404 on agent.connskill.com and connskill.com
openid_configuration: 404 on every host
note: There is no OAuth to discover; payment gates access.
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.