Green Helix · Authentication Profile
Greenhelix Net Authentication
Authentication
Green Helix secures its APIs with apiKey and http across 3 declared security schemes, as derived from its OpenAPI definitions.
AgentsAgentic CommercePaymentsEscrowBillingMarketplaceIdentityTrustMessagingWebhookMCPA2Ax402
Methods: apiKey, http
Schemes: 3
OAuth flows:
API key in: header
Security Schemes
BearerAuth http
scheme: bearer
ApiKeyAuth apiKey
· in: header (X-API-Key)
X402Payment apiKey
· in: header (X-PAYMENT)
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/greenhelix-net-a2a-commerce-gateway-openapi.yml (three securitySchemes) upgraded from https://www.greenhelix.net/docs.html#authentication,
https://github.com/mirni/a2a/blob/main/docs/api-reference.md#1-authentication and https://github.com/mirni/a2a/blob/main/docs/adr/009-auth-rate-limiting.md;
401 shapes observed live 2026-09-19
summary:
types:
- apiKey
- http
api_key_in:
- header
style: Opaque per-agent API key with the tier embedded in the prefix; no OAuth, no OIDC, no JWT (ADR-009). x402
payment proof accepted as a stateless alternative when enabled.
schemes:
- name: BearerAuth
type: http
scheme: bearer
description: API key passed as Bearer token in the Authorization header.
sources:
- openapi/greenhelix-net-a2a-commerce-gateway-openapi.yml
- name: ApiKeyAuth
type: apiKey
in: header
parameter: X-API-Key
description: API key passed directly in the X-API-Key header (alternative to Bearer).
sources:
- openapi/greenhelix-net-a2a-commerce-gateway-openapi.yml
- name: X402Payment
type: apiKey
in: header
parameter: X-PAYMENT
description: x402 payment proof for stateless authentication.
sources:
- openapi/greenhelix-net-a2a-commerce-gateway-openapi.yml
docs:
- https://www.greenhelix.net/docs.html
- https://github.com/mirni/a2a/blob/main/docs/api-reference.md#1-authentication
- https://github.com/mirni/a2a/blob/main/docs/adr/009-auth-rate-limiting.md
api_key:
format: 'a2a_{tier}_{24_hex_chars} (tiers: free, starter, pro, enterprise; e.g. a2a_free_… )'
issuance: 'Self-service: POST /v1/register {"agent_id"} (no auth) creates a wallet, a free-tier key and an identity
in one step; POST /v1/billing/keys (create_billing_api_key) issues further keys; POST /v1/infra/keys is the
deprecated older route.'
storage: Plaintext returned exactly once at creation; stored server-side as a SHA-3-256 hash (api-reference) /
SHA-256 (ADR-009).
rotation: POST /v1/infra/keys/rotate {current_key} with optional X-Rotate-Confirmation header (revoke old, issue
new at the same tier); POST /v1/infra/keys/revoke.
header_precedence:
- 'Authorization: Bearer <key> (preferred)'
- 'X-API-Key: <key>'
scoping: Tier-scoped (free 100/h … enterprise 100000/h); a key can act only for its own agent_id — 403 forbidden
when creating keys for another agent.
x402:
header: X-PAYMENT
encoding: base64-encoded JSON payment proof
when: when no API key is provided and x402 payment verification is enabled on the gateway
settlement: on-chain USDC micropayments
errors:
402 payment_required: no key and x402 enabled
402 payment_verification_failed: proof invalid
402 payment_replay_detected: nonce already used
note: Declared as securitySchemes.X402Payment and applied globally; not exercised live in this pass (unauthenticated
calls answered 401 missing-key, no 402 challenge observed).
observed:
- request: GET https://api.greenhelix.net/v1/billing/wallets/example-agent/balance (no credentials)
status: 401
content_type: application/problem+json
body:
type: https://api.greenhelix.net/errors/missing-key
title: Unauthorized
detail: Missing API key
www_authenticate: null
- request: 'same, Authorization: Bearer a2a_free_<unknown>'
status: 401
body:
type: https://api.greenhelix.net/errors/authentication-error
title: Unauthorized
detail: API key not found
- request: GET https://api.greenhelix.net/v1/metrics
status: 403
body:
type: https://api.greenhelix.net/errors/forbidden
detail: Metrics requires enterprise tier or allowed IP
public_endpoints:
- GET /v1/health, /livez, /readyz
- GET /v1/pricing, /v1/pricing/{tool}, /v1/pricing/summary, /v1/pricing/tiers
- GET /v1/openapi.json, /v1/onboarding, /docs, /redoc
- GET /.well-known/agent-card.json, /.well-known/ai-plugin.json
- POST /v1/register
oauth:
supported: false
note: No oauth2/openIdConnect scheme; /.well-known/oauth-authorization-server, oauth-protected-resource and openid-configuration
all 404 on api, sandbox and www hosts. No scopes artifact is written.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/greenhelix-net-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.