Cymetica · Authentication Profile

Cymetica Com Authentication

Authentication

Cymetica secures its APIs with apiKey, http, and oauth2 across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

Prediction MarketsCryptocurrency ExchangeTradingAI AgentsMCPAgent-NativeBlockchainDeFiFinancial ServicesMarket DataA2AReal-Time
Methods: apiKey, http, oauth2 Schemes: 4 OAuth flows: authorizationCode API key in: header

Security Schemes

ApiKeyAuth apiKey
· in: header (X-API-Key)
BearerJWT http
scheme: bearer
OAuth2 oauth2
· flows: authorizationCode
HMAC (api_secret) custom

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/cymetica-com-eventtrader-public-api-openapi.yml
summary:
  types:
  - apiKey
  - http
  - oauth2
  api_key_in:
  - header
  oauth2_flows:
  - authorizationCode
  docs_upgrade: 'Three documented ways in: (1) register + POST /auth/api-key under a JWT, (2) one-call bootstrap
    POST /auth/api-key with email+password, (3) POST /mcp/v1/register for an instant mcp_ agent key. Plus OAuth
    2.0 authorization-code with PKCE S256 (RFC 8414 + RFC 9728 discovery, RFC 7591 registration) whose tokens work
    on REST but not on /mcp/v1, and SIWE wallet sign-in via the Python SDK. A 401 carries WWW-Authenticate: Bearer
    and {"detail": "Authentication required. Provide Bearer token or X-API-Key header."}.'
schemes:
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter: X-API-Key
  sources:
  - openapi/cymetica-com-eventtrader-public-api-openapi.yml
  key_prefixes:
    user: evt_
    agent: mcp_
  issuance:
  - POST /auth/api-key (JWT or email+password bootstrap) -> api_key + api_secret
  - POST /api/v1/api-keys (session JWT only) -> named key with permissions {read, trade, withdraw}
  - POST /mcp/v1/register (no auth) -> mcp_ key, trust_level recognized
  permissions:
  - read
  - trade
  - withdraw (registered agent keys only; user keys and OAuth tokens cannot withdraw)
  storage: SHA-256 hashed; plaintext shown once
- name: BearerJWT
  type: http
  scheme: bearer
  bearerFormat: JWT
  description: Account session JWT (from /auth/login). Key-management routes accept only this — never an API key.
  sources:
  - openapi/cymetica-com-eventtrader-public-api-openapi.yml
  issuance:
  - POST /auth/login (email/password) -> access_token + refresh_token
  - POST /auth/register
  - SIWE wallet sign-in (EventTrader.from_wallet in the Python SDK)
- name: OAuth2
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://cymetica.com/oauth/authorize
    tokenUrl: https://cymetica.com/oauth/token
    scopes: 3
  sources:
  - openapi/cymetica-com-eventtrader-public-api-openapi.yml
  discovery:
    authorization_server_metadata: well-known/cymetica-com-oauth-authorization-server.json
    protected_resource_metadata: well-known/cymetica-com-oauth-protected-resource.json
    registration_endpoint: https://cymetica.com/oauth/register
    revocation_endpoint: https://cymetica.com/oauth/revoke
    userinfo_endpoint: https://cymetica.com/oauth/userinfo
    pkce: S256
    grant_types:
    - authorization_code
    - refresh_token
    token_endpoint_auth_methods:
    - none
    - client_secret_post
    - client_secret_basic
  note: OAuth bearer tokens work on the REST API (/api/v1/*); the /mcp/v1 JSON-RPC endpoint uses X-API-Key (mcp.json
    authentication.oauth.note).
- name: HMAC (api_secret)
  type: custom
  status: mentioned-not-specified
  description: POST /auth/api-key returns an api_secret "for HMAC-signed integrations" (docs); the signing scheme
    is not documented in the spec or the docs.
  sources:
  - https://cymetica.com/api-docs
  - https://cymetica.com/getting-started
docs: https://cymetica.com/api-docs#authentication
sources_searched:
- https://cymetica.com/api-docs (Authentication, API Key Management)
- https://cymetica.com/getting-started
- https://cymetica.com/sdk (Authentication)
- https://cymetica.com/.well-known/oauth-authorization-server
- https://cymetica.com/.well-known/oauth-protected-resource
- https://cymetica.com/.well-known/mcp.json
- live 401 probe of GET /api/v1/portfolio/positions
mcp:
  endpoint: https://cymetica.com/mcp/v1
  anonymous_access: 57 public tools with no credentials
  header: X-API-Key
  trust_tiers:
  - unknown
  - recognized
  - trusted
  - allied

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cymetica-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.