Scro Orphan Desk · Authentication Profile

Dualregistry Dev Authentication

Authentication

Scro Orphan Desk secures its APIs with none and x402-payment-proof across 3 declared security schemes, as derived from its OpenAPI definitions.

AI Agentsx402A2ADeFiCryptoStablecoinsPaymentsIntent TradingMachine EconomyAgent-Native
Methods: none, x402-payment-proof Schemes: 3 OAuth flows: API key in:

Security Schemes

none none
x402-payment-proof payment
orphandust-credit-token bearer-like-credit

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: >-
  openapi/dualregistry-dev-openapi.yml (no securitySchemes, no security — derive-authentication.py
  produced nothing), upgraded from https://dualregistry.dev/llms.txt ("Per-Echo GET (x402 paywall)",
  "OBO→pay"), https://dualregistry.dev/AGENT.md, the agent card's x402_paywall block,
  well-known/dualregistry-dev-ai-plugin.json (auth {type: none}), well-known/dualregistry-dev-x402.json,
  the live 402 responses on /api/echo and /api/orphandust/buy (headers + body), the CORS
  Access-Control-Allow-Headers list observed on every /api/* response, and the provider's
  vercel.json / verify_payment.js in github.com/manhatton31-svg/orphan-desk-source.
docs: https://dualregistry.dev/llms.txt
checked: '2026-09-19'
summary:
  types: [none, x402-payment-proof]
  model: no-identity-payment-is-the-gate
  model_note: >-
    There is no authentication: no API key, no token, no OAuth, no signup, no account. The
    ai-plugin manifest says auth {type: none} and the OpenAPI declares no securitySchemes. Access
    control is economic — the free surfaces (index, stats, fill_hint, catalogs, previews,
    exploratory quotes, non-open echoes) answer 200 to anyone, and the paid surface (an open echo's
    unsealed legs, an OrphanDust credit) answers HTTP 402 with an x402 v1 invoice until the same
    request is retried carrying proof of an on-chain stablecoin transfer to the desk's receive
    wallet, which the server verifies against the chain ("fail-closed") before serving. Three proof
    forms exist: payment-proof headers (or the equivalent query parameters), a quote_id that binds
    a negotiated price, and a credit_token bought through OrphanDust.
  oauth2: false
  openid_connect: false
  mtls: false
  api_key_in: []
  scopes: false
  scopes_note: 'No scopes/ artifact and no OAuthScopes pointer: nothing declares oauth2 or any permission model.'
schemes:
- name: none
  type: none
  declared_in_spec: 'implicitly — no securitySchemes, no security requirement on any of the 7 operations'
  applies_to: [listEchoes, getStats, 'redeemEcho with ?preview=1 or on a non-open echo', 'quoteFee exploratory (firm false/omitted)', 'GET /fill_hint.json, /PROMO.json, /ORPHANDUST.json, /PRODUCT.json, /SPOTLIGHT.json, /DIRECTORY.json, /MIRROR.json, /ACROSS.json', 'GET /api/feedback (self-description)']
  sources: ['well-known/dualregistry-dev-ai-plugin.json auth.type none', 'https://dualregistry.dev/llms.txt']
- name: x402-payment-proof
  type: payment
  standard: x402 v1
  declared_in_spec: 'as the 402 responses on redeemEcho, quoteFee and buyOrphanDustCredits; not a securityScheme (OpenAPI has no type for it)'
  applies_to: ['redeemEcho on an open echo (GET /api/echo?echo_id=, GET /*.echo.json)', 'quoteFee firm accept (402 invoice with quote_id)', 'buyOrphanDustCredits (402 for the SKU)']
  challenge:
    status: 402
    headers_observed: ['PAYMENT-REQUIRED: <base64 JSON {x402Version: 1, accepts[]}>', 'x-payment-required: true', 'x402-asset: USDC', 'x402-network: eip155:8453', 'x402-pay-to: 0x459cF7359e37B45A0d2a2479656cD96cdA9F7dBb', 'x402-price: 0.50']
    body: 'application/json type x402_payment_required with accepts[] (scheme exact, network eip155:8453 | base, USDC asset 0x8335…2913, maxAmountRequired in 6-decimal units, maxTimeoutSeconds 600) and accepted[] (USDC/Base preferred; USDT/BSC; USDC and USDT on Ethereum)'
  proof:
    headers: ['X-PAYMENT-TX (0x… transaction hash)', 'X-PAYMENT-CHAIN (base|bsc|ethereum)', 'X-PAYMENT-ASSET (USDC|USDT, optional)', 'X-PAYMENT-AMOUNT (optional)', 'X-PAYMENT-PAYER (optional)', 'X-PAYMENT (generic x402 header, allowed by CORS)', 'PAYMENT-TX / PAYMENT-CHAIN (unprefixed aliases, allowed by CORS)']
    query_equivalents: [tx_hash, chain, asset, amount]
    binding_headers: ['X-QUOTE-ID — binds a firm quote (final_usdc) to the unlock; quote TTL 20 minutes', 'X-CREDIT-TOKEN or ?credit_token=odc_… — spends one OrphanDust unlock credit instead of a per-echo fee', 'X-BOND-WAIVER — bond waiver id (bond is 0; kept for compatibility)']
    verification_verbatim: 'Server RPC-verifies Transfer to fee wallet (fail-closed) then auto settle_fee.'
    manual_path: 'POST /api/settle_fee {quote_id|echo_id, tx_hash, chain, amount_usdc|amount, asset?, payer?} -> receipt (same RPC verification)'
  receive_wallet: 0x459cF7359e37B45A0d2a2479656cD96cdA9F7dBb
  receive_wallet_note: 'One EVM address on Ethereum (eip155:1), Base (eip155:8453) and BSC (eip155:56); published in every JSON document, the x402 discovery file and the agent card''s agentWallet services.'
  sources: ['https://dualregistry.dev/llms.txt', 'https://dualregistry.dev/.well-known/x402', 'live 402 on GET /api/echo?echo_id=echo_a25e7551ed53c3018600f816 (2026-09-19)', 'https://dualregistry.dev/AGENT.md step 6']
- name: orphandust-credit-token
  type: bearer-like-credit
  declared_in_spec: false
  applies_to: ['POST /api/orphandust/unlock {echo_id, credit_token}', 'GET /api/echo?echo_id=…&credit_token=odc_…']
  how: 'Buy a SKU at POST /api/orphandust/buy (402 -> pay 0.50 USDC on Base -> retry with X-PAYMENT-TX + X-PAYMENT-CHAIN) and receive credits; a credit_token (prefix odc_) spends one credit per unlock. Refusals: invalid_credit_token, credit_expired, credit_exhausted (source orphandust.js). Credit TTL not published.'
  sources: ['https://dualregistry.dev/ORPHANDUST.json', 'live 402 on GET /api/orphandust/buy', 'GET /api/orphandust/unlock -> 405 note']
agent_guidance: >-
  Do not look for a key. Read /index.json free, preview an echo free with ?preview=1, quote free
  with firm omitted, and only when you intend to pay follow the 402: pay the accepts[] amount in
  USDC on Base to payTo, then repeat the SAME request with X-PAYMENT-TX and X-PAYMENT-CHAIN. The
  payment is an irreversible on-chain transfer — see conventions/ (reversibility: none).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dualregistry-dev-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.