Hergert Synthora · Authentication Profile

Hergertsynthora Com Authentication

Authentication

Hergert Synthora secures its APIs with apiKey and http across 3 declared security schemes, as derived from its OpenAPI definitions.

CompanyAgentsA2AMCPx402Web3Sanctions ScreeningPrediction MarketsOSINTBlockchainSpain
Methods: apiKey, http Schemes: 3 OAuth flows: API key in: header

Security Schemes

x402Payment apiKey
· in: header (X-PAYMENT)
x402 http
scheme: x402
wallet apiKey
· in: header (X-WALLET)

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: >-
  Derived baseline from openapi/hergertsynthora-com-mesh-aggregate-openapi.yml (securitySchemes.x402Payment) by
  0-working/derive-authentication.py, then upgraded from the provider's own auth statements: the agent card
  securitySchemes (x402 http scheme + X-WALLET apiKey), https://hergertsynthora.com/api/ (X-WALLET on core
  endpoints, 403 without it), https://api.hergertsynthora.com/llms.txt (free tier), the notary card and the live
  402 responses observed 2026-09-19 (WWW-Authenticate x402 challenge, payment-required header, x-free-tier).
docs: https://hergertsynthora.com/api/
summary:
  types:
  - apiKey
  - http
  api_key_in:
  - header
  model: >-
    Wallet-native, accountless. There is no sign-up, no API key issuance and no OAuth. A paid call authenticates
    itself by carrying a payment (X-PAYMENT); an unpaid trial call identifies itself by its wallet address
    (X-WALLET). The 59 per-service OpenAPIs and the notary spec declare NO securitySchemes at all - the
    requirement lives in info.x-payment / x-payment-info and the 402 response.
schemes:
- name: x402Payment
  type: apiKey
  in: header
  parameter: X-PAYMENT
  description: >-
    EIP-3009 transferWithAuthorization payload, USDC on Base (eip155:8453). Obtained by first calling the
    endpoint and reading the 402 challenge (accepts[] in the body; the same JSON base64url in the
    payment-required header; on the api gateway also a WWW-Authenticate: x402 network=..., asset=..., pay_to=...,
    max_amount=..., resource=... challenge).
  applies_to: every paid operation (global security in the aggregate; implied by x-payment-info in every per-service spec)
  sources:
  - openapi/hergertsynthora-com-mesh-aggregate-openapi.yml
  - live 402 on https://api.hergertsynthora.com/v1/wallet-enrich and https://notary.hergertsynthora.com/service
- name: x402
  type: http
  scheme: x402
  description: >-
    How the agent cards declare the same requirement: "Pago por llamada x402: USDC en Base (eip155:8453). La
    primera llamada devuelve HTTP 402 con los terminos de pago; el pago se verifica on-chain y la respuesta
    incluye recibo firmado." Not an IANA-registered HTTP auth scheme; recorded because the live gateway does
    emit a WWW-Authenticate challenge with that token.
  sources:
  - a2a/hergertsynthora-com-agent-card.json (securitySchemes.x402)
  - a2a/hergertsynthora-com-notary-agent-card.json (securitySchemes.x402)
- name: wallet
  type: apiKey
  in: header
  parameter: X-WALLET
  description: >-
    The caller's Base address (0x...). Two uses the provider documents: (1) free trial - send it instead of a
    payment and the product answers up to x-free-tier calls (1 or 3, per product) without charge; (2) the
    "nucleo" state and meshgraph endpoints treat it as an API key and answer 403 without it (docs section 02;
    the docs elide the host for those endpoints).
  sources:
  - a2a/hergertsynthora-com-agent-card.json (securitySchemes.wallet)
  - https://hergertsynthora.com/api/
  - https://api.hergertsynthora.com/llms.txt
  - 402 body freeTier {callsPerWallet, header X-WALLET}; response header x-free-tier
credentials:
  sign_up: none - no accounts; the wallet is the identity
  key_prefixes: none
  rotation: n/a
  sandbox_keys: none (see sandbox/hergertsynthora-com-sandbox.yml)
transport:
  https_only: true
  tls: TLSv1.3 on apex, api and notary hosts (security/hergertsynthora-com-domain-security.yml)
  mcp: https://mcp.hergertsynthora.com/mcp - initialize and tools/list are anonymous; tools/call is x402-paid; no OAuth metadata served
  a2a: https://api.hergertsynthora.com/a2a - JSON-RPC, same x402 / X-WALLET model per the card's security[]
gaps:
- The per-service and notary OpenAPIs declare no securitySchemes, so a generic OpenAPI client sees them as unauthenticated.
- The X-WALLET "nucleo" endpoints are documented without a host.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hergertsynthora-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.