Scro Orphan Desk · Authentication Profile
Dualregistry Dev Authentication
Authentication
Scro Orphan Desk secures its APIs with none and x402-payment-proof across 3 declared security schemes, as derived from its OpenAPI definitions.
AI Agentsx402A2ADeFiCryptoStablecoinsPaymentsIntent TradingMachine EconomyAgent-Native
Methods: none, x402-payment-proof
Schemes: 3
OAuth flows:
API key in:
Security Schemes
none none
x402-payment-proof payment
orphandust-credit-token bearer-like-credit
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: >-
openapi/dualregistry-dev-openapi.yml (no securitySchemes, no security — derive-authentication.py
produced nothing), upgraded from https://dualregistry.dev/llms.txt ("Per-Echo GET (x402 paywall)",
"OBO→pay"), https://dualregistry.dev/AGENT.md, the agent card's x402_paywall block,
well-known/dualregistry-dev-ai-plugin.json (auth {type: none}), well-known/dualregistry-dev-x402.json,
the live 402 responses on /api/echo and /api/orphandust/buy (headers + body), the CORS
Access-Control-Allow-Headers list observed on every /api/* response, and the provider's
vercel.json / verify_payment.js in github.com/manhatton31-svg/orphan-desk-source.
docs: https://dualregistry.dev/llms.txt
checked: '2026-09-19'
summary:
types: [none, x402-payment-proof]
model: no-identity-payment-is-the-gate
model_note: >-
There is no authentication: no API key, no token, no OAuth, no signup, no account. The
ai-plugin manifest says auth {type: none} and the OpenAPI declares no securitySchemes. Access
control is economic — the free surfaces (index, stats, fill_hint, catalogs, previews,
exploratory quotes, non-open echoes) answer 200 to anyone, and the paid surface (an open echo's
unsealed legs, an OrphanDust credit) answers HTTP 402 with an x402 v1 invoice until the same
request is retried carrying proof of an on-chain stablecoin transfer to the desk's receive
wallet, which the server verifies against the chain ("fail-closed") before serving. Three proof
forms exist: payment-proof headers (or the equivalent query parameters), a quote_id that binds
a negotiated price, and a credit_token bought through OrphanDust.
oauth2: false
openid_connect: false
mtls: false
api_key_in: []
scopes: false
scopes_note: 'No scopes/ artifact and no OAuthScopes pointer: nothing declares oauth2 or any permission model.'
schemes:
- name: none
type: none
declared_in_spec: 'implicitly — no securitySchemes, no security requirement on any of the 7 operations'
applies_to: [listEchoes, getStats, 'redeemEcho with ?preview=1 or on a non-open echo', 'quoteFee exploratory (firm false/omitted)', 'GET /fill_hint.json, /PROMO.json, /ORPHANDUST.json, /PRODUCT.json, /SPOTLIGHT.json, /DIRECTORY.json, /MIRROR.json, /ACROSS.json', 'GET /api/feedback (self-description)']
sources: ['well-known/dualregistry-dev-ai-plugin.json auth.type none', 'https://dualregistry.dev/llms.txt']
- name: x402-payment-proof
type: payment
standard: x402 v1
declared_in_spec: 'as the 402 responses on redeemEcho, quoteFee and buyOrphanDustCredits; not a securityScheme (OpenAPI has no type for it)'
applies_to: ['redeemEcho on an open echo (GET /api/echo?echo_id=, GET /*.echo.json)', 'quoteFee firm accept (402 invoice with quote_id)', 'buyOrphanDustCredits (402 for the SKU)']
challenge:
status: 402
headers_observed: ['PAYMENT-REQUIRED: <base64 JSON {x402Version: 1, accepts[]}>', 'x-payment-required: true', 'x402-asset: USDC', 'x402-network: eip155:8453', 'x402-pay-to: 0x459cF7359e37B45A0d2a2479656cD96cdA9F7dBb', 'x402-price: 0.50']
body: 'application/json type x402_payment_required with accepts[] (scheme exact, network eip155:8453 | base, USDC asset 0x8335…2913, maxAmountRequired in 6-decimal units, maxTimeoutSeconds 600) and accepted[] (USDC/Base preferred; USDT/BSC; USDC and USDT on Ethereum)'
proof:
headers: ['X-PAYMENT-TX (0x… transaction hash)', 'X-PAYMENT-CHAIN (base|bsc|ethereum)', 'X-PAYMENT-ASSET (USDC|USDT, optional)', 'X-PAYMENT-AMOUNT (optional)', 'X-PAYMENT-PAYER (optional)', 'X-PAYMENT (generic x402 header, allowed by CORS)', 'PAYMENT-TX / PAYMENT-CHAIN (unprefixed aliases, allowed by CORS)']
query_equivalents: [tx_hash, chain, asset, amount]
binding_headers: ['X-QUOTE-ID — binds a firm quote (final_usdc) to the unlock; quote TTL 20 minutes', 'X-CREDIT-TOKEN or ?credit_token=odc_… — spends one OrphanDust unlock credit instead of a per-echo fee', 'X-BOND-WAIVER — bond waiver id (bond is 0; kept for compatibility)']
verification_verbatim: 'Server RPC-verifies Transfer to fee wallet (fail-closed) then auto settle_fee.'
manual_path: 'POST /api/settle_fee {quote_id|echo_id, tx_hash, chain, amount_usdc|amount, asset?, payer?} -> receipt (same RPC verification)'
receive_wallet: 0x459cF7359e37B45A0d2a2479656cD96cdA9F7dBb
receive_wallet_note: 'One EVM address on Ethereum (eip155:1), Base (eip155:8453) and BSC (eip155:56); published in every JSON document, the x402 discovery file and the agent card''s agentWallet services.'
sources: ['https://dualregistry.dev/llms.txt', 'https://dualregistry.dev/.well-known/x402', 'live 402 on GET /api/echo?echo_id=echo_a25e7551ed53c3018600f816 (2026-09-19)', 'https://dualregistry.dev/AGENT.md step 6']
- name: orphandust-credit-token
type: bearer-like-credit
declared_in_spec: false
applies_to: ['POST /api/orphandust/unlock {echo_id, credit_token}', 'GET /api/echo?echo_id=…&credit_token=odc_…']
how: 'Buy a SKU at POST /api/orphandust/buy (402 -> pay 0.50 USDC on Base -> retry with X-PAYMENT-TX + X-PAYMENT-CHAIN) and receive credits; a credit_token (prefix odc_) spends one credit per unlock. Refusals: invalid_credit_token, credit_expired, credit_exhausted (source orphandust.js). Credit TTL not published.'
sources: ['https://dualregistry.dev/ORPHANDUST.json', 'live 402 on GET /api/orphandust/buy', 'GET /api/orphandust/unlock -> 405 note']
agent_guidance: >-
Do not look for a key. Read /index.json free, preview an echo free with ?preview=1, quote free
with firm omitted, and only when you intend to pay follow the 402: pay the accepts[] amount in
USDC on Base to payTo, then repeat the SAME request with X-PAYMENT-TX and X-PAYMENT-CHAIN. The
payment is an irreversible on-chain transfer — see conventions/ (reversibility: none).
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dualregistry-dev-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.