Hilt · Authentication Profile

Hilt So Authentication

Authentication

Hilt declares 6 security scheme(s) across its OpenAPI definitions.

PaymentsSolanaStablecoinsUSDCCrypto PaymentsAgentic Paymentsx402CheckoutSubscriptionWebhookMCPEntitlementsMicropaymentsDeveloper ToolsFintechA2A
Methods: Schemes: 6 OAuth flows: API key in:

Security Schemes

HiltApiKey apiKey
· in: header ()
DashboardBearer http
scheme: bearer
PayMeOAuth oauth2
x402PaymentSignature payment-protocol
MPPPaymentCredential payment-protocol
WebhookSignature hmac

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://docs.hilt.so/developers/api-keys; https://docs.hilt.so/developers/access; https://docs.hilt.so/developers/quickstart;
  https://docs.hilt.so/developers/payment-channels; https://api.hilt.so/.well-known/oauth-authorization-server (probed);
  openapi/hilt-so-openapi.yml (header parameters)
docs: https://docs.hilt.so/developers/api-keys
spec_gap: The published OpenAPI declares NO components.securitySchemes and no security requirements on any of its
  165 operations; every scheme below is documented in prose or discoverable from RFC 8414/9728 metadata. derive-authentication.py
  therefore produced nothing and this profile is hand-built from the docs.
schemes:
- name: HiltApiKey
  type: apiKey
  in: header
  header: X-Hilt-Key
  key_prefixes:
    live: hk_live_
    sandbox: hk_sandbox_
  applies_to: Workspace merchant routes (/v1/products, /v1/memberships, /v1/receipts, /v1/support, /v1/testing)
    and Hilt Pay API routes (/v1/access/*)
  permissions:
  - access:read - check entitlements and read Pay API rails
  - access:write - create Pay API apps, products, and payment sessions
  - access:webhooks - register webhook endpoints for Pay API flows
  management: Dashboard -> Advanced; GET/POST /v1/keys, DELETE /v1/keys/{key_id}; CLI hilt keys *. Raw key shown
    once; rotation = create replacement, deploy, GET /v1/products to confirm, revoke old.
  unauthenticated_response:
    status: 401
    body: '{"detail":"Authentication required"}'
    probed: GET /v1/account/me and POST /v1/access/entitlements/consume, 2026-09-19
- name: DashboardBearer
  type: http
  scheme: bearer
  header: 'Authorization: Bearer <token>'
  applies_to: 'Dashboard/session routes: /v1/auth/*, /v1/account/*, /v1/webhooks/endpoints (quickstart uses Bearer
    for webhook endpoint creation and test events), /v1/keys, /v1/billing/*'
  obtain: POST /v1/auth/login, POST /v1/auth/wallet (wallet-signature login), /v1/auth/oauth/{provider}/start; refresh
    via POST /v1/auth/refresh; CLI hilt login
  note: Postman environment variable bearerToken.
- name: PayMeOAuth
  type: oauth2
  flow: authorizationCode
  pkce: S256 required
  authorizationUrl: https://api.hilt.so/oauth/authorize
  tokenUrl: https://api.hilt.so/oauth/token
  registrationUrl: https://api.hilt.so/oauth/register (RFC 7591 dynamic client registration)
  revocationUrl: https://api.hilt.so/oauth/revoke
  refresh: refresh_token grant supported
  client_auth: none (public clients)
  scopes:
    pay_me:read: Read connector-started payments and received activity
    pay_me:request: Create and manage self-shared payment links
    pay_me:prepare: Start and manage wallet-approved payments to verified PayMe handles
  resource: https://api.hilt.so/mcp/pay-me (RFC 9728 metadata at /.well-known/oauth-protected-resource/mcp/pay-me)
  identity: Sign in with X supplies the PayMe identity
  discovery: well-known/hilt-so-api-oauth-authorization-server.json
- name: x402PaymentSignature
  type: payment-protocol
  protocol: x402 V2
  headers:
    challenge: PAYMENT-REQUIRED (HTTP 402 response; base64 payment requirement)
    proof: PAYMENT-SIGNATURE (request header on retry; declared as a header parameter on POST /v1/access/x402/settle
      and on /v1/solana/transaction-evidence)
    result: PAYMENT-RESPONSE (response header after settlement)
  settlement: Solana USDC (network solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp per the agent-commerce offer)
  applies_to: Merchant-protected resources; Hilt agent-commerce plan activation; the transaction-evidence resource
    (0.05 USDC/request); paid MCP gateway tools
  note: 'Not a credential for Hilt itself: the buyer never receives the merchant X-Hilt-Key.'
- name: MPPPaymentCredential
  type: payment-protocol
  protocol: Machine Payments Protocol (MPP) over HTTP 402
  headers:
    challenge: 'WWW-Authenticate: Payment'
    credential: 'Authorization: Payment <MPP credential>'
    receipt: Payment-Receipt (successful responses)
  applies_to: MPP metered session channels (/v1/access/metered-sessions/*) and the public PayMe agent payment action
    POST /v1/pay-me/payments (no payer account, OAuth grant or API key)
  on_chain_program: CHNLxYvVA28MJP9PrFuDXccuoGXAx7jBacfLEkahyGsX (Solana mainnet channel program)
- name: WebhookSignature
  type: hmac
  header: X-Hilt-Signature
  format: t=<unix_timestamp>,v1=<hex_hmac_sha256>
  signed_payload: <timestamp>.<raw_json_body>
  algorithm: HMAC-SHA256 with the endpoint signing secret
  direction: Hilt -> merchant (verify inbound webhooks)
  also: Stripe-Signature header parameter on POST /v1/billing/webhooks/stripe (Hilt account billing inbound from
    Stripe)
request_id_headers:
- X-Hilt-Request-Id
- X-Request-Id
summary: API key (X-Hilt-Key, hk_live_/hk_sandbox_) for merchants and Pay API; bearer session tokens for the dashboard
  surface; OAuth 2.1-style PKCE with DCR for the PayMe MCP connector; x402 V2 and MPP payment credentials for paid
  requests; HMAC-signed webhooks.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hilt-so-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.