Qorevia · Authentication Profile
Flowhomes Eu Authentication
Authentication
Qorevia declares 2 security scheme(s) across its OpenAPI definitions.
Market DataGoldXAUUSDTradingFinanceQuantitative ResearchRisk ManagementData ProfilingDeveloper Toolsx402USDCBase L2Agentic Commercepay-per-callMCPA2AAgentsAgent-Native
Methods:
Schemes: 2
OAuth flows:
API key in:
Security Schemes
payment (x402 v2) — not an OpenAPI securityScheme type
none
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: https://api.flowhomes.eu/skill.md
docs: https://api.flowhomes.eu/skill.md
summary: >-
There is no authentication. openapi/flowhomes-eu-openapi.json declares no securitySchemes and no
security requirement (derive-authentication.py correctly produced nothing), and that is accurate: the
provider states "No API key required for paid routes" (agent card, skill qorevia-x402-seller) and
"There are no accounts". Access control is PAYMENT: each of the 13 priced operations answers an
unpaid request with HTTP 402 and a PAYMENT-REQUIRED header carrying x402 v2 requirements, and serves
the response when the same request is retried with a PAYMENT-SIGNATURE header proving a USDC transfer
on Base Mainnet. The 21 free routes, the MCP server and the A2A endpoint need nothing at all. No
OAuth, OIDC or RFC 9728 metadata is served (all 404 on api.flowhomes.eu, which is also the MCP host).
schemes:
- id: x402-payment
type: payment (x402 v2) — not an OpenAPI securityScheme type
declared_in_spec: false
applies_to: [session_state, risk_levels, strategy_grade, xau_quote, xau_bars, xau_market_state, csv_profile, json_shape, jwt_decode, tick_pnl, evm_address_syntax, ohlcv_state, regex_test]
challenge:
http_status: 402
header: PAYMENT-REQUIRED
encoding: base64(JSON)
observed: >-
{x402Version 2, error "Payment required", resource {url, description, mimeType application/json},
accepts[{scheme exact, network eip155:8453, amount "5000", asset
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payTo 0x80cdA9077d65Ac1a05454619Bb94B318cf0c3382,
maxTimeoutSeconds 300, extra {name "USD Coin", version "2"}}], extensions.bazaar {...}} — GET
/api/session-state, 2026-09-19.
body: '{}'
credential:
header: PAYMENT-SIGNATURE
what: an x402 v2 payment payload proving settlement of accepts[].amount in USDC to payTo on eip155:8453, produced by an x402 client, optionally through the facilitator https://facilitator.payai.network
lifetime: maxTimeoutSeconds 300 from the challenge
docs_quote: 'Clients should make the request normally, read the HTTP 402 payment requirements, pay using x402, and retry with PAYMENT-SIGNATURE.'
manifest: https://api.flowhomes.eu/.well-known/x402
facilitator: https://facilitator.payai.network
key_prefixes: none (no keys)
optional_headers:
- name: X-Qorevia-Ref
purpose: 'Founders Network referral attribution on a paid call (or the ?ref=QF-... query parameter); not an authenticator'
- id: none
type: none
applies_to: ['GET /api/find', 'POST /api/route', 'GET /api/catalog', 'GET /api/try', 'POST /mcp', 'POST /a2a', 'GET /health', 'GET /dashboard', 'GET /api/stats', 'the four qorevia-* beacons', '/api/magnet*', '/api/amplifier/stats', '/api/distribution/stats', 'the /api/club* Founders Network routes', '/party']
note: Anonymous. The club routes identify a caller by a public wallet address supplied in the request (invalid_wallet otherwise); that is an identifier, not a credential.
oauth: null
openid_connect: null
mutual_tls: null
api_keys: null
mcp_auth:
endpoint: https://api.flowhomes.eu/mcp
scheme: none — initialize, tools/list and tools/call answered anonymously
protected_resource_metadata: 404 (/.well-known/oauth-protected-resource)
authorization_server_metadata: 404 (/.well-known/oauth-authorization-server)
a2a_auth:
endpoint: https://api.flowhomes.eu/a2a
scheme: none — the card declares no securitySchemes; message/send completed anonymously
signup: none — no accounts exist; a funded USDC wallet on Base is the only prerequisite
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/flowhomes-eu-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.