X402 AI 自助门店 · Authentication Profile

Easyfence Cn Authentication

Authentication

The provider's OpenAPI declares NO securitySchemes and no security requirement on any operation, so derive-authentication.py produced nothing. The real access model is not HTTP authentication at all: the public surface is anonymous, the paid surface is gated by an x402 payment (HTTP 402 with a payment requirement, satisfied by an EIP-3009 USDC transfer authorization), identity is an ERC-8004 style card verified out-of-band, and the operator console is gated by a shared token in a query string. Every entry below was observed live on 2026-09-19.

X402 AI 自助门店 secures its APIs with none, x402-payment, erc8004-identity, and query-token across 4 declared security schemes, as derived from its OpenAPI definitions.

Agentic CommerceAI AgentsA2Ax402PaymentsStablecoinsAgent IdentityContent GenerationWeb3
Methods: none, x402-payment, erc8004-identity, query-token Schemes: 4 OAuth flows: API key in:

Security Schemes

anonymous none
x402 payment
scheme: x402 exact (x402Version 1)
erc8004 identity
scheme: ERC-8004 style identity card, EIP-712 signed
adminToken apiKey
· in: query ()

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: probed
source:
- https://www.easyfence.cn/openapi.json
- https://www.easyfence.cn/.well-known/agent.json
- https://www.easyfence.cn/api/deliver (POST, live 402 challenge)
- https://www.easyfence.cn/a2a (GET explainer page)
- https://www.easyfence.cn/admin
docs: https://www.easyfence.cn/a2a
spec: openapi/easyfence-cn-store-api-openapi.yml
description: >-
  The provider's OpenAPI declares NO securitySchemes and no security requirement on any operation, so
  derive-authentication.py produced nothing. The real access model is not HTTP authentication at all: the
  public surface is anonymous, the paid surface is gated by an x402 payment (HTTP 402 with a payment
  requirement, satisfied by an EIP-3009 USDC transfer authorization), identity is an ERC-8004 style card
  verified out-of-band, and the operator console is gated by a shared token in a query string. Every
  entry below was observed live on 2026-09-19.
summary:
  types: [none, x402-payment, erc8004-identity, query-token]
  transport: HTTPS; the payment authorization travels in the retried request per the x402 protocol
schemes:
- name: anonymous
  type: none
  surface: >-
    GET /api/catalog, GET /api/registry, GET /healthz, GET /facilitator/healthz, GET /.well-known/agent.json,
    POST /api/identity/verify, POST /a2a
  description: >-
    No credential of any kind. The catalog, the trust registry, both health endpoints, the agent card and
    the A2A JSON-RPC endpoint all answered without headers. The agent card declares no securitySchemes and
    no security, so an A2A client will read the agent as unauthenticated.
  probes:
  - {url: 'https://www.easyfence.cn/api/catalog', method: GET, status: 200}
  - {url: 'https://www.easyfence.cn/api/registry', method: GET, status: 200}
  - {url: 'https://www.easyfence.cn/api/identity/verify', method: 'POST {}', status: 200, body: '{"ok":false,"reason":"字段缺失"}', note: reachable anonymously; answered "fields missing"}
  - {url: 'https://www.easyfence.cn/a2a', method: POST tasks/get, status: 400, body: JSON-RPC -32601}
- name: x402
  type: payment
  scheme: x402 exact (x402Version 1)
  surface: POST /api/deliver
  description: >-
    The delivery endpoint answers HTTP 402 Payment Required with an x402 payment-requirements body until
    the buyer presents a signed payment. accepts[] offers two routes for the same 0.50 USD service:
    scheme "exact" on network base (chainId 8453, asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 = USDC,
    maxAmountRequired 500000 = 0.50 USDC at 6 decimals, facilitator https://x402.org/facilitator) and
    scheme "exact" on network bsc (chainId 56, asset 0x8AC76a51cc950d9822D68b83fE1Ad97B32Cd580d,
    maxAmountRequired 500000000000000000 = 0.50 at 18 decimals, facilitator https://www.easyfence.cn/facilitator).
    Both pay to 0xF9E7138dDC630EFa202B56bBDca42466F5F25B93 with maxTimeoutSeconds 60. The /a2a explainer says
    the buyer signs an EIP-3009 authorization and retries. /healthz reports payment_mode "mainnet-real":
    this is live money, not a sandbox. The Base route also carries an x402 "bazaar" extension with an input
    JSON Schema for the request body (service, params.brief, optional buyer_agent).
  probes:
  - {url: 'https://www.easyfence.cn/api/deliver', method: 'POST {"service":"write_script","params":{"brief":"probe"}}', status: 402, content_type: application/json, headers: 'accept: exact', note: full x402 payment-requirements body returned; no payment was made}
  - {url: 'https://www.easyfence.cn/api/deliver', method: 'POST {}', status: 400, body: '{"error":"未知服务","known":[...7 ids]}', note: an unknown service is rejected BEFORE the payment gate}
- name: erc8004
  type: identity
  scheme: ERC-8004 style identity card, EIP-712 signed
  surface: POST /api/identity/verify, POST /api/identity/issue, GET /api/registry
  description: >-
    The card's auth.identity is "erc8004" and the home page describes step two of a sale as the buyer
    presenting an ERC-8004 on-chain identity card that the store verifies. /api/identity/verify accepts a
    presented card and answers {ok, reason}; /api/identity/issue (marked demo in its own description) signs
    a card for an agent address with the store issuer key; /api/registry publishes the issuer
    (0x63D4b01ecba21a15c324559dd324928fe57b3Bbe) and trusted_issuers (currently the same address) with
    count 0 agents. Identity is presented as data, not as an HTTP credential, and nothing observed
    requires it: the 402 challenge was returned to an unidentified caller.
  probes:
  - {url: 'https://www.easyfence.cn/api/registry', method: GET, status: 200, body: '{"registry":"X402 ERC-8004 Trust Registry","issuer":"0x63D4...3Bbe","trusted_issuers":[...],"count":0,"agents":[]}'}
- name: adminToken
  type: apiKey
  in: query
  name_param: token
  surface: GET /admin, GET|POST /admin/config, GET /admin/revenue, GET|POST /admin/services
  description: >-
    The operator console answers 401 with an HTML hint "访问 /admin?token=你的ADMIN_TOKEN" (visit
    /admin?token=YOUR_ADMIN_TOKEN). A single shared secret in the query string; not a public developer
    credential and not probed further.
  probes:
  - {url: 'https://www.easyfence.cn/admin', method: GET, status: 401, content_type: text/html}
oauth: false
openid_connect: false
api_keys: false
notes: >-
  /.well-known/oauth-authorization-server, /.well-known/oauth-protected-resource and
  /.well-known/openid-configuration all 404 on both hosts. No scopes/ artifact is written because there
  is no scope surface. The spec's silence on security is itself a finding: an agent reading the OpenAPI
  alone cannot learn that /api/deliver costs money until it receives the 402.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/easyfence-cn-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.