Hergert Synthora · Authentication Profile
Hergertsynthora Com Authentication
Authentication
Hergert Synthora secures its APIs with apiKey and http across 3 declared security schemes, as derived from its OpenAPI definitions.
CompanyAgentsA2AMCPx402Web3Sanctions ScreeningPrediction MarketsOSINTBlockchainSpain
Methods: apiKey, http
Schemes: 3
OAuth flows:
API key in: header
Security Schemes
x402Payment apiKey
· in: header (X-PAYMENT)
x402 http
scheme: x402
wallet apiKey
· in: header (X-WALLET)
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: >-
Derived baseline from openapi/hergertsynthora-com-mesh-aggregate-openapi.yml (securitySchemes.x402Payment) by
0-working/derive-authentication.py, then upgraded from the provider's own auth statements: the agent card
securitySchemes (x402 http scheme + X-WALLET apiKey), https://hergertsynthora.com/api/ (X-WALLET on core
endpoints, 403 without it), https://api.hergertsynthora.com/llms.txt (free tier), the notary card and the live
402 responses observed 2026-09-19 (WWW-Authenticate x402 challenge, payment-required header, x-free-tier).
docs: https://hergertsynthora.com/api/
summary:
types:
- apiKey
- http
api_key_in:
- header
model: >-
Wallet-native, accountless. There is no sign-up, no API key issuance and no OAuth. A paid call authenticates
itself by carrying a payment (X-PAYMENT); an unpaid trial call identifies itself by its wallet address
(X-WALLET). The 59 per-service OpenAPIs and the notary spec declare NO securitySchemes at all - the
requirement lives in info.x-payment / x-payment-info and the 402 response.
schemes:
- name: x402Payment
type: apiKey
in: header
parameter: X-PAYMENT
description: >-
EIP-3009 transferWithAuthorization payload, USDC on Base (eip155:8453). Obtained by first calling the
endpoint and reading the 402 challenge (accepts[] in the body; the same JSON base64url in the
payment-required header; on the api gateway also a WWW-Authenticate: x402 network=..., asset=..., pay_to=...,
max_amount=..., resource=... challenge).
applies_to: every paid operation (global security in the aggregate; implied by x-payment-info in every per-service spec)
sources:
- openapi/hergertsynthora-com-mesh-aggregate-openapi.yml
- live 402 on https://api.hergertsynthora.com/v1/wallet-enrich and https://notary.hergertsynthora.com/service
- name: x402
type: http
scheme: x402
description: >-
How the agent cards declare the same requirement: "Pago por llamada x402: USDC en Base (eip155:8453). La
primera llamada devuelve HTTP 402 con los terminos de pago; el pago se verifica on-chain y la respuesta
incluye recibo firmado." Not an IANA-registered HTTP auth scheme; recorded because the live gateway does
emit a WWW-Authenticate challenge with that token.
sources:
- a2a/hergertsynthora-com-agent-card.json (securitySchemes.x402)
- a2a/hergertsynthora-com-notary-agent-card.json (securitySchemes.x402)
- name: wallet
type: apiKey
in: header
parameter: X-WALLET
description: >-
The caller's Base address (0x...). Two uses the provider documents: (1) free trial - send it instead of a
payment and the product answers up to x-free-tier calls (1 or 3, per product) without charge; (2) the
"nucleo" state and meshgraph endpoints treat it as an API key and answer 403 without it (docs section 02;
the docs elide the host for those endpoints).
sources:
- a2a/hergertsynthora-com-agent-card.json (securitySchemes.wallet)
- https://hergertsynthora.com/api/
- https://api.hergertsynthora.com/llms.txt
- 402 body freeTier {callsPerWallet, header X-WALLET}; response header x-free-tier
credentials:
sign_up: none - no accounts; the wallet is the identity
key_prefixes: none
rotation: n/a
sandbox_keys: none (see sandbox/hergertsynthora-com-sandbox.yml)
transport:
https_only: true
tls: TLSv1.3 on apex, api and notary hosts (security/hergertsynthora-com-domain-security.yml)
mcp: https://mcp.hergertsynthora.com/mcp - initialize and tools/list are anonymous; tools/call is x402-paid; no OAuth metadata served
a2a: https://api.hergertsynthora.com/a2a - JSON-RPC, same x402 / X-WALLET model per the card's security[]
gaps:
- The per-service and notary OpenAPIs declare no securitySchemes, so a generic OpenAPI client sees them as unauthenticated.
- The X-WALLET "nucleo" endpoints are documented without a host.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hergertsynthora-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.