AIScan · Authentication Profile

Getaiscan App Authentication

Authentication

AIScan secures its APIs with apiKey across 1 declared security scheme, as derived from its OpenAPI definitions.

AI VisibilityWebsite AuditingSEOAnswer Engine OptimizationGenerative Engine OptimizationAgentsAgentic CommerceA2AMCPx402Agent-Native
Methods: apiKey Schemes: 1 OAuth flows: API key in: header

Security Schemes

x402 apiKey
· in: header (PAYMENT-SIGNATURE)

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/getaiscan-app-openapi.json
docs:
- https://getaiscan.app/llms.txt
- https://api.getaiscan.app/api/agent/index
- https://getaiscan.app/.well-known/agent-card.json
summary:
  types:
  - apiKey
  api_key_in:
  - header
  oauth2_flows: []
  bearer: false
  credential_classes: 1
  headline: >-
    No API key, no account, no signup, no OAuth. The single securityScheme in the contract is named "x402" and
    typed apiKey-in-header only because OpenAPI has no vocabulary for a payment credential: the header
    PAYMENT-SIGNATURE carries an x402 V2 payment — either a signed EIP-3009 "exact" authorization for USDC on
    Base settled through the Coinbase CDP facilitator, or the transaction hash of a direct USDC transfer to the
    provider's wallet. An unpaid call to any paid route returns HTTP 402 with a base64 PAYMENT-REQUIRED header
    and a JSON body naming the price, asset, network, recipient and both flows. GET /api/agent/index is the only
    unauthenticated route (security: []).
schemes:
- name: x402
  type: apiKey
  in: header
  parameter: PAYMENT-SIGNATURE
  description: 'x402 V2 payment: signed payload or Base USDC tx hash'
  semantics: payment credential, not an identity credential — the paying wallet is the only identity the API sees
  protocol:
    name: x402
    version: 2
    network: eip155:8453 (Base mainnet)
    asset: USDC — 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
    pay_to: '0x0a28ace35b9687a9334cd503b3c7d4b23734a1c7'
    flows:
    - id: exact
      description: EIP-3009 transferWithAuthorization signed by the payer, settled via the Coinbase CDP facilitator; the signed payload goes in PAYMENT-SIGNATURE.
    - id: direct-transfer
      description: Send the exact USDC amount on Base to pay_to, then retry the same request with PAYMENT-SIGNATURE set to the transaction hash.
    max_timeout_seconds: 300
  challenge_observed:
    request: 'POST https://api.getaiscan.app/api/agent/check_health {"url":"https://example.com"} with no payment header, 2026-09-19'
    status: 402
    headers:
      payment-required: base64 JSON — {x402Version 2, error "PAYMENT-SIGNATURE header is required", resource {url, description, mimeType}, accepts [{scheme exact, network eip155:8453, amount 60000, asset, payTo, maxTimeoutSeconds 300, extra {name USD Coin, version 2}}], extensions {}}
      x-payment-required: 'true'
      x-payment-version: '2'
      x-payment-amount: '0.06'
      x-payment-currency: USDC
      x-payment-network: eip155:8453
      x-payment-recipient: '0x0a28ace35b9687a9334cd503b3c7d4b23734a1c7'
      x-payment-asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'
    body_fields: [x402Version, error, resource, accepts, extensions, price, currency, recipient, instructions, capability, index]
    instructions_verbatim: >-
      Pay 0.06 USDC: x402 V2 'exact' scheme (PAYMENT-SIGNATURE header, settled via Coinbase CDP facilitator),
      or direct-transfer: send 0.06 USDC on Base (eip155:8453) to 0x0a28ace35b9687a9334cd503b3c7d4b23734a1c7
      and retry with PAYMENT-SIGNATURE: <tx_hash>
    note: The body's accepts[0].network says "base" while the header and the PAYMENT-REQUIRED payload say "eip155:8453"; the amount is in USDC base units (60000 = 0.06 USDC, 6 decimals).
  header_aliases:
    accepted_by_cors: [PAYMENT-SIGNATURE, Payment-Signature, X-Payment, X-PAYMENT]
    note: The legacy agent.json descriptor and the mcp.json descriptor name X-Payment; the OpenAPI, the agent card and the live challenge name PAYMENT-SIGNATURE. Use PAYMENT-SIGNATURE.
  applied_to: every POST /api/agent/{capability} operation (19 of 20 operations); the operations declare no per-operation security[] and the document declares no top-level security, so the requirement is expressed by the 402 response each operation declares rather than by a security requirement object
  exempt: [index]
  sources:
  - openapi/getaiscan-app-openapi.json
gaps:
- The OpenAPI declares the x402 scheme in components.securitySchemes but applies it nowhere (no top-level or per-operation security[] except index's empty list); a client generator will treat every operation as anonymous.
- No OAuth/OIDC, no RFC 9728 protected-resource metadata, no RFC 8414 metadata on either host; there is nothing to discover beyond the 402 itself.
- No testnet or sandbox payment path is documented; every call is a real mainnet USDC payment.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/getaiscan-app-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.