openclaw / evm-lab · Authentication Profile

Evebrief Org Authentication

Authentication

openclaw / evm-lab declares 0 security scheme(s) across its OpenAPI definitions.

AgentsA2Ax402XRPLBlockchainDeFiEVMSecurityFraud PreventionRisk ManagementAgent-NativeMarket Intelligence
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/evebrief-org-openapi.json
docs:
- https://oracle.evebrief.org/.well-known/agent-card.json
- https://oracle.evebrief.org/.well-known/x402
summary:
  types: []
  api_key_in: []
  oauth2_flows: []
  bearer: false
  credential_classes: 0
  payment_gated: true
  headline: >-
    No credential of any kind. The OpenAPI declares no securitySchemes (derive-authentication.py found
    nothing to derive), the agent card declares no securitySchemes or security, and no OAuth/OIDC discovery
    document exists on either host. Access to the one functional operation (POST /) is gated by PAYMENT, not
    identity: an unpaid call returns HTTP 402 with x402 v2 PaymentRequirements and the retry carries a
    PAYMENT-SIGNATURE header proving settlement of 0.01 RLUSD on the XRP Ledger through the t54 facilitator.
    The four GET routes (both card paths, the x402 manifest, /healthz) are free and anonymous.
schemes: []
payment_gate:
  name: x402
  standard: x402 v2 (HTTP 402 payment challenge)
  request_header: PAYMENT-SIGNATURE
  challenge_header: PAYMENT-REQUIRED (base64 JSON PaymentRequirements; the same object is the 402 body)
  observed: 'GET and POST https://oracle.evebrief.org/ without the header -> 402, body error "PAYMENT-SIGNATURE header is required", fresh invoiceId per challenge (2026-09-19)'
  requirements:
    scheme: exact
    network: 'xrpl:0 (XRP Ledger mainnet)'
    asset: RLUSD (hex 524C555344000000000000000000000000000000)
    issuer: rMxCKbEDwqr76QuheSUMdEGf4B9xJ8m5De
    amount: '0.01'
    pay_to: rH2tcNh56xoLUssRubra7DSDCgrReSZodW
    facilitator: https://xrpl-facilitator-mainnet.t54.ai
    max_timeout_seconds: 600
  applies_to: [jsonrpc__post]
  free_operations: [agent_card__well_known_agent_json_get, agent_card_alt__well_known_agent_card_json_get, x402_manifest__well_known_x402_get, healthz_healthz_get]
  sources:
  - a2a/evebrief-org-agent-card.json (capabilities.extensions[0], required true)
  - well-known/evebrief-org-x402.json
  - errors/evebrief-org-problem-types.yml (the observed 402)
  note: >-
    Recorded as a payment gate rather than an apiKey scheme on purpose: PAYMENT-SIGNATURE is not a static
    credential a caller holds, it is a per-invoice proof of settlement, and modelling it as an API key would
    tell an agent to go looking for a key that is never issued. No identity, no account, no scopes.
discovery:
- {url: 'https://oracle.evebrief.org/.well-known/oauth-authorization-server', status: 404}
- {url: 'https://oracle.evebrief.org/.well-known/oauth-protected-resource', status: 404}
- {url: 'https://oracle.evebrief.org/.well-known/openid-configuration', status: 404}
- {url: 'https://evebrief.org/.well-known/oauth-authorization-server', status: 404}
- {url: 'https://evebrief.org/.well-known/openid-configuration', status: 404}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/evebrief-org-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.