Verified Digital Agents (VDA) · Authentication Profile
Getvda Ai Authentication
Authentication
Verified Digital Agents (VDA) secures its APIs with http, oauth2, and x402-payment across 7 declared security schemes, as derived from its OpenAPI definitions.
CompanyAI AgentsAI GovernanceComplianceAudit TrailAgent IdentityA2AMCPx402EU AI ActHuman-in-the-Loop
Methods: http, oauth2, x402-payment
Schemes: 7
OAuth flows:
API key in:
Security Schemes
witnessApiKey http
scheme: bearer
controllerKey signature
scheme: Ed25519 challenge-response
google_oauth2 oauth2
· flows:
microsoft_oauth2 oauth2
· flows: ,
approver_oidc http
scheme: bearer
· in: header ()
tenantBearer http
scheme: bearer
x402 payment
scheme: x402 v2 (HTTP 402 challenge)
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: https://witness.getvda.ai/llms.txt
derived_from:
- openapi/getvda-ai-witness-openapi.json
- openapi/getvda-ai-hitl-openapi.json
- openapi/getvda-ai-acp-openapi.json
- a2a/getvda-ai-c2md-agent-card.json
- a2a/getvda-ai-onboard-agent-card.json
- well-known/getvda-ai-agents-ai-catalog.json
docs:
- https://witness.getvda.ai/docs
- https://witness.getvda.ai/llms.txt
- https://c2md.getvda.ai/llms.txt
- https://agents.getvda.ai/llms.txt
summary:
types: [http, oauth2, x402-payment]
model: >-
One suite credential minted by Witness and validated everywhere else through Witness GET /whoami ("Contract A"):
`Authorization: Bearer wtn.<keyId>.<secret>`. Witness also accepts the same key in an `x-witness-key` header. The
key is short-lived by design (quick-start keys expire in 7 days) and is renewed unattended by Ed25519
controller-key challenge-response, so the durable identity is the account (acct_<ULID>) plus a controller key
the caller holds, not a standing secret. There is no OAuth authorization server on any VDA host; C2MD delegates
human sign-in to Google and Microsoft Entra, ACP declares an OIDC approver credential it does not yet enforce
(readyz: identity disabled), Onboarding uses a per-tenant bearer, and the GOSCE fleet has no authentication at
all — execution is gated by x402 payment.
observed:
- {request: 'POST https://witness.getvda.ai/api/witness/seal (no header)', status: 401, body: '{"error":"unknown or invalid API key"}'}
- {request: 'POST https://hitl.getvda.ai/mcp (no header)', status: 401, body: '{"error":"unauthorized","message":"missing bearer credential"}'}
- {request: 'POST https://witness.getvda.ai/api/witness/mcp tools/list (no header)', status: 200, note: discovery is anonymous}
schemes:
- name: witnessApiKey
aka: witness_bearer / bearerAuth (HITL) — the same credential under three scheme names
type: http
scheme: bearer
bearerFormat: wtn.<keyId>.<secret>
alternate_header: x-witness-key
issued_by: 'POST https://witness.getvda.ai/api/witness/test-key (self-serve, instant, no human) — also the MCP tool get_test_key and the card''s provisioning.selfServeKey'
renewal: 'POST /api/witness/renew/challenge -> Ed25519-sign sign_payload "vda.witness.renew/1|<accountId>|<nonce>" with the bound controller key -> POST /api/witness/renew; prior keys stay valid until expiry'
revocation: 'POST /api/witness/keys/revoke — total and itself sealed as a key_revocation event'
validation: 'siblings call GET /api/witness/whoami -> {account_id, tier SEALED|ANCHORED, scopes [seal, read], compliance, key_id, revoked, expires_at}; 200 is Cache-Control private max-age=60, 401 is generic + no-store'
used_by:
- witness.getvda.ai
- hitl.getvda.ai (every method incl. MCP initialize)
- acp.getvda.ai (/v1 routes)
- 'c2md.getvda.ai (generative tools; account tier maps to c2md:* scopes)'
public_exceptions:
- 'POST /api/witness/verify'
- 'GET /api/witness/credentials/{credential_id}'
- 'GET /api/witness/records/{recordId}/issuer'
- 'POST /api/witness/test-key'
- 'renew/challenge + renew (controller signature instead)'
- 'MCP initialize/tools/list on Witness and C2MD'
- 'ACP GET /bundles/*'
sources: [openapi/getvda-ai-witness-openapi.json, openapi/getvda-ai-hitl-openapi.json, openapi/getvda-ai-acp-openapi.json, a2a/getvda-ai-c2md-agent-card.json]
- name: controllerKey
type: signature
scheme: Ed25519 challenge-response
description: >-
Not a request credential but the root of the account: an Ed25519 public JWK ({kty OKP, crv Ed25519, x}) bound at
mint time or via POST /api/witness/account/bind-controller. Authorises key renewal and controller-signed key
revocation; "there is no standing credential to leak". Distinct from the record-signing key (customer-managed
custody, published at the issuer's did:web) and the did:web card-signing key — the docs call out THREE keys.
sources: [https://witness.getvda.ai/llms.txt]
- name: google_oauth2
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://accounts.google.com/o/oauth2/v2/auth
tokenUrl: https://oauth2.googleapis.com/token
scopes: [c2md:assess, c2md:generate_starter, c2md:generate_pro, c2md:generate_journey, c2md:commercial_deploy]
description: Google Sign-In for Workspace and personal accounts; token validated via Google's JWKS; used for C2MD skill-tier scope assertion against subscription state.
used_by: [c2md.getvda.ai]
sources: [a2a/getvda-ai-c2md-agent-card.json]
- name: microsoft_oauth2
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize
tokenUrl: https://login.microsoftonline.com/organizations/oauth2/v2.0/token
scopes: [c2md:assess, c2md:generate_starter, c2md:generate_pro, c2md:generate_journey, c2md:commercial_deploy]
clientCredentials:
tokenUrl: https://login.microsoftonline.com/organizations/oauth2/v2.0/token
scopes: ['7c89fa90-05ca-4779-8128-32c7f11f604b/.default']
description: Microsoft Entra ID, organisations only (personal accounts unsupported); clientCredentials is for pre-registered service principals (Tier 3, by arrangement — hello@getvda.ai).
used_by: [c2md.getvda.ai]
sources: [a2a/getvda-ai-c2md-agent-card.json]
- name: approver_oidc
type: http
scheme: bearer
in: header
header: X-Approver-Credential
description: An OIDC token from the customer's IdP identifying a human approver on ACP's decision route. DECLARED but not live — GET https://acp.getvda.ai/readyz reports identity "disabled" ("set OIDC_ISSUER + OIDC_AUDIENCE to enable").
used_by: [acp.getvda.ai]
status: staged
sources: [a2a/getvda-ai-acp-agent-card.json, openapi/getvda-ai-acp-openapi.json]
- name: tenantBearer
type: http
scheme: bearer
description: Per-tenant service-account token for the Onboarding agent's admit_agent, revoke_credential and get_admission_status skills.
used_by: [onboard.getvda.ai]
sources: [a2a/getvda-ai-onboard-agent-card.json]
- name: x402
type: payment
scheme: x402 v2 (HTTP 402 challenge)
description: >-
The GOSCE fleet (98 servers + router) requires NO authentication; metered tools answer 402 with a base64
PAYMENT-REQUIRED header and are retried with a PAYMENT-SIGNATURE header — an EIP-3009 transferWithAuthorization
in USDC on Base (eip155:8453) or an nvm:card-delegation Stripe checkout for humans. The C2MD card notes
generated Copilot Studio connectors are "remote streamable-HTTP MCP servers requiring NO authentication".
used_by: ['*.getvda.ai fleet', router.getvda.ai]
sources: [well-known/getvda-ai-agents-ai-catalog.json, https://agents.getvda.ai/llms.txt]
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/getvda-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.