Virix Labs · Authentication Profile

Humanbrowser Cloud Authentication

Authentication

Virix Labs secures its APIs with http, apiKey, and oauth2 across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials (declared in the OpenAPI; tokenUrl dead) and authorizationCode + PKCE (live on agent.humanbrowser.cloud via RFC 8414 metadata; undocumented) flow(s).

Browser AutomationCloud BrowserAI AgentsA2AMCPWeb ScrapingResidential ProxiesCAPTCHA SolvingHuman-in-the-LoopComputer UseAgent-NativeUnited Kingdom
Methods: http, apiKey, oauth2 Schemes: 4 OAuth flows: clientCredentials (declared in the OpenAPI; tokenUrl dead), authorizationCode + PKCE (live on agent.humanbrowser.cloud via RFC 8414 metadata; undocumented) API key in: cookie

Security Schemes

bearerAuth http
scheme: bearer
sessionCookie apiKey
· in: cookie (hb_session)
oauth2 oauth2
· flows: clientCredentials
mcp-oauth (RFC 8414 / RFC 9728, not in the OpenAPI) oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/humanbrowser-cloud-openapi.json
docs:
- https://humanbrowser.cloud/docs/mcp
- https://humanbrowser.cloud/a2a
- https://agent.humanbrowser.cloud/.well-known/oauth-authorization-server
- https://agent.humanbrowser.cloud/.well-known/oauth-protected-resource
summary:
  types:
  - http
  - apiKey
  - oauth2
  api_key_in:
  - cookie
  oauth2_flows:
  - clientCredentials (declared in the OpenAPI; tokenUrl dead)
  - authorizationCode + PKCE (live on agent.humanbrowser.cloud via RFC 8414 metadata; undocumented)
  bearer: true
  credential_classes: 4
  headline: >-
    One prepaid-balance bearer token (hb_live_...) is the credential every published integration uses —
    the A2A endpoint, the hosted MCP endpoint, the stdio MCP server (HB_TOKEN env, legacy alias
    HUMANBROWSER_API_TOKEN), the SDK, the CLI and the token-scoped REST operations. A dashboard session
    cookie (hb_session) guards getAccount. The OpenAPI also declares an oauth2 clientCredentials scheme
    with three scopes whose tokenUrl 404s, and the agent host serves a live OAuth 2.1 authorization server
    (authorization code + PKCE S256, client-ID metadata documents or DCR ids hbc_<32hex>, scopes mcp:run /
    mcp:read) advertised for the MCP resource by RFC 9728 metadata — but no documentation page describes
    that flow (service_documentation /docs/oauth 404) and every guide says "use the bearer token".
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  token_prefix: hb_live_
  description: 'Human Browser API token (hb_live_… or trial). Send as Authorization: Bearer <token>.'
  issuance:
    trial: POST /api/trial-balance {email} (claimTrial) — $10 balance, one per email, revoked after 14 days without a top-up
    paid: issued on first top-up; the card says POST /api/buy returns a fresh token by webhook after a crypto payment
    dashboard: https://humanbrowser.cloud/account
  used_by: [topUp, getUsage, runA2ATask, 'POST /mcp (hosted MCP)', 'GET /api/balance on the agent host (CLI balance; not in the OpenAPI)']
  observed:
  - {url: 'POST https://agent.humanbrowser.cloud/mcp', status: 401, www_authenticate: 'Bearer realm="humanbrowser-mcp"', body: '{"error":"unauthorized","hint":"Authorization: Bearer hb_live_<token>"}'}
  - {url: 'POST https://agent.humanbrowser.cloud/a2a', status: 401, body: 'JSON-RPC error -32001 Unauthorized, data.hint "Authorization: Bearer <token>"'}
  - {url: 'GET https://humanbrowser.cloud/api/usage', status: 401, body: '{"error":"Unauthorized. Pass Authorization: Bearer <DEPLOY_SECRET>"}', note: 'the live route asks for a deployment secret, not a customer token'}
  rules: ['never put the token in a URL query string (agent card)', 'the MCP endpoint refuses non-Bearer auth', 'tokens are hashed at rest (Privacy 10)', 'report a suspected compromise by email (Terms 3)']
  sources:
  - openapi/humanbrowser-cloud-openapi.json
  - https://humanbrowser.cloud/docs/mcp
- name: sessionCookie
  type: apiKey
  in: cookie
  parameter: hb_session
  description: Login session cookie for account endpoints.
  used_by: [getAccount]
  observed:
  - {url: 'GET https://humanbrowser.cloud/api/account', status: 400, body: '{"error":"bad-token"}', note: 'without a cookie or token'}
  sources:
  - openapi/humanbrowser-cloud-openapi.json
- name: oauth2
  type: oauth2
  flows:
  - flow: clientCredentials
    tokenUrl: https://agent.humanbrowser.cloud/oauth/token
    scopes: 3
    scope_list: [session:run, account:read, account:topup]
  description: Least-privilege scoped access. Request only the scopes an agent needs.
  used_by: [getAccount (account:read), topUp (account:topup), getUsage (account:read), runA2ATask (session:run)]
  status: declared but not reachable
  observed:
  - {url: 'https://agent.humanbrowser.cloud/oauth/token', method: GET, status: 404}
  - {url: 'https://agent.humanbrowser.cloud/oauth/token', method: POST, status: 404, body: '{"error":"not-found","path":"/oauth/token"}'}
  sources:
  - openapi/humanbrowser-cloud-openapi.json
- name: mcp-oauth (RFC 8414 / RFC 9728, not in the OpenAPI)
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://agent.humanbrowser.cloud/authorize
    tokenUrl: https://agent.humanbrowser.cloud/token
    refreshUrl: https://agent.humanbrowser.cloud/token
    registrationUrl: https://agent.humanbrowser.cloud/register
    revocationUrl: https://agent.humanbrowser.cloud/revoke
    pkce: S256 required (only method listed)
    client_auth: [none, client_secret_post]
    client_ids: 'CIMD URL (https://) or DCR id hbc_<32hex>'
    scopes: [mcp:run, mcp:read]
  resource: https://agent.humanbrowser.cloud/mcp
  description: The OAuth 2.1 door an MCP client following RFC 9728 discovery would find; scopes and endpoints from the two well-known documents. No human-readable documentation exists for it.
  status: live but undocumented
  observed:
  - {url: 'GET /authorize', status: 400, body: 'unsupported_response_type — response_type must be code'}
  - {url: 'GET /authorize?response_type=code&client_id=probe', status: 400, body: 'invalid_client — client_id must be CIMD URL (https://) or DCR id (hbc_<32hex>)'}
  - {url: 'POST /token (empty form)', status: 400, body: 'unsupported_grant_type — grant_type must be authorization_code or refresh_token'}
  - {url: 'GET /token', status: 404}
  - {url: 'GET /register', status: 404, note: 'POST not attempted (would register a client)'}
  - {url: 'https://humanbrowser.cloud/docs/oauth (service_documentation)', status: 404}
  sources:
  - well-known/humanbrowser-cloud-oauth-authorization-server.json
  - well-known/humanbrowser-cloud-oauth-protected-resource.json
a2a_card_scheme:
  http_bearer: {type: http, scheme: bearer, description: 'Skill token issued by humanbrowser.cloud. Required on every /a2a call.'}
  security: [{http_bearer: []}]
environment_variables:
  HB_TOKEN: canonical since 5.0.2 (stdio MCP server, CLI)
  HUMANBROWSER_API_TOKEN: legacy alias, still accepted
  HB_API_BASE / HUMANBROWSER_API_BASE: 'override the agent host (default https://agent.humanbrowser.cloud)'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/humanbrowser-cloud-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.