Green Helix · Authentication Profile

Greenhelix Net Authentication

Authentication

Green Helix secures its APIs with apiKey and http across 3 declared security schemes, as derived from its OpenAPI definitions.

AgentsAgentic CommercePaymentsEscrowBillingMarketplaceIdentityTrustMessagingWebhookMCPA2Ax402
Methods: apiKey, http Schemes: 3 OAuth flows: API key in: header

Security Schemes

BearerAuth http
scheme: bearer
ApiKeyAuth apiKey
· in: header (X-API-Key)
X402Payment apiKey
· in: header (X-PAYMENT)

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/greenhelix-net-a2a-commerce-gateway-openapi.yml (three securitySchemes) upgraded from https://www.greenhelix.net/docs.html#authentication,
  https://github.com/mirni/a2a/blob/main/docs/api-reference.md#1-authentication and https://github.com/mirni/a2a/blob/main/docs/adr/009-auth-rate-limiting.md;
  401 shapes observed live 2026-09-19
summary:
  types:
  - apiKey
  - http
  api_key_in:
  - header
  style: Opaque per-agent API key with the tier embedded in the prefix; no OAuth, no OIDC, no JWT (ADR-009). x402
    payment proof accepted as a stateless alternative when enabled.
schemes:
- name: BearerAuth
  type: http
  scheme: bearer
  description: API key passed as Bearer token in the Authorization header.
  sources:
  - openapi/greenhelix-net-a2a-commerce-gateway-openapi.yml
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter: X-API-Key
  description: API key passed directly in the X-API-Key header (alternative to Bearer).
  sources:
  - openapi/greenhelix-net-a2a-commerce-gateway-openapi.yml
- name: X402Payment
  type: apiKey
  in: header
  parameter: X-PAYMENT
  description: x402 payment proof for stateless authentication.
  sources:
  - openapi/greenhelix-net-a2a-commerce-gateway-openapi.yml
docs:
- https://www.greenhelix.net/docs.html
- https://github.com/mirni/a2a/blob/main/docs/api-reference.md#1-authentication
- https://github.com/mirni/a2a/blob/main/docs/adr/009-auth-rate-limiting.md
api_key:
  format: 'a2a_{tier}_{24_hex_chars}  (tiers: free, starter, pro, enterprise; e.g. a2a_free_… )'
  issuance: 'Self-service: POST /v1/register {"agent_id"} (no auth) creates a wallet, a free-tier key and an identity
    in one step; POST /v1/billing/keys (create_billing_api_key) issues further keys; POST /v1/infra/keys is the
    deprecated older route.'
  storage: Plaintext returned exactly once at creation; stored server-side as a SHA-3-256 hash (api-reference) /
    SHA-256 (ADR-009).
  rotation: POST /v1/infra/keys/rotate {current_key} with optional X-Rotate-Confirmation header (revoke old, issue
    new at the same tier); POST /v1/infra/keys/revoke.
  header_precedence:
  - 'Authorization: Bearer <key> (preferred)'
  - 'X-API-Key: <key>'
  scoping: Tier-scoped (free 100/h … enterprise 100000/h); a key can act only for its own agent_id — 403 forbidden
    when creating keys for another agent.
x402:
  header: X-PAYMENT
  encoding: base64-encoded JSON payment proof
  when: when no API key is provided and x402 payment verification is enabled on the gateway
  settlement: on-chain USDC micropayments
  errors:
    402 payment_required: no key and x402 enabled
    402 payment_verification_failed: proof invalid
    402 payment_replay_detected: nonce already used
  note: Declared as securitySchemes.X402Payment and applied globally; not exercised live in this pass (unauthenticated
    calls answered 401 missing-key, no 402 challenge observed).
observed:
- request: GET https://api.greenhelix.net/v1/billing/wallets/example-agent/balance (no credentials)
  status: 401
  content_type: application/problem+json
  body:
    type: https://api.greenhelix.net/errors/missing-key
    title: Unauthorized
    detail: Missing API key
  www_authenticate: null
- request: 'same, Authorization: Bearer a2a_free_<unknown>'
  status: 401
  body:
    type: https://api.greenhelix.net/errors/authentication-error
    title: Unauthorized
    detail: API key not found
- request: GET https://api.greenhelix.net/v1/metrics
  status: 403
  body:
    type: https://api.greenhelix.net/errors/forbidden
    detail: Metrics requires enterprise tier or allowed IP
public_endpoints:
- GET /v1/health, /livez, /readyz
- GET /v1/pricing, /v1/pricing/{tool}, /v1/pricing/summary, /v1/pricing/tiers
- GET /v1/openapi.json, /v1/onboarding, /docs, /redoc
- GET /.well-known/agent-card.json, /.well-known/ai-plugin.json
- POST /v1/register
oauth:
  supported: false
  note: No oauth2/openIdConnect scheme; /.well-known/oauth-authorization-server, oauth-protected-resource and openid-configuration
    all 404 on api, sandbox and www hosts. No scopes artifact is written.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/greenhelix-net-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.