HumanMirror · Authentication Profile

Humanmirror Fr Authentication

Authentication

HumanMirror secures its APIs with http bearer (per-product prefixed API keys), apiKey in header (X-API-Key, HumanMirror Pro), x402 payment signature (PAYMENT-SIGNATURE header, not an OpenAPI securityScheme), and none (discovery, quotes, verification, Magnet, MCP tools/list) across 11 declared security schemes, as derived from its OpenAPI definitions.

CompanyAI AgentsAgent SecurityPrompt Injection Defensex402Machine PaymentsUSDCMCPA2AData QualityVerified OutcomesMicrotransactionsFrance
Methods: http bearer (per-product prefixed API keys), apiKey in header (X-API-Key, HumanMirror Pro), x402 payment signature (PAYMENT-SIGNATURE header, not an OpenAPI securityScheme), none (discovery, quotes, verification, Magnet, MCP tools/list) Schemes: 11 OAuth flows: API key in:

Security Schemes

HumanMirrorProApiKey apiKey
· in: header (X-API-Key)
EnterpriseBearer http
scheme: bearer
OmniSyncApiKey http
scheme: bearer
ApiKeyBearer http
scheme: bearer
BearerAuth http
scheme: bearer
BearerAuth http
scheme: bearer
NexusBearer http
scheme: bearer
BearerAuth http
scheme: bearer
BearerAuth http
scheme: bearer
BearerAuth http
scheme: bearer
bearerAuth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://humanmirror.fr/connect/, https://humanmirror.fr/docs/vibecode/, https://humanmirror.fr/llms.txt,
  https://humanmirror.fr/skill.md, https://humanmirror.fr/.well-known/mcp.json, /forge-mcp.json, /nexus.json, the
  three registry server.json files, and every securityScheme in the 16 contracts under openapi/ (listed verbatim
  below); live 402 challenge observed 2026-09-19
docs: null
summary:
  types:
  - http bearer (per-product prefixed API keys)
  - apiKey in header (X-API-Key, HumanMirror Pro)
  - x402 payment signature (PAYMENT-SIGNATURE header, not an OpenAPI securityScheme)
  - none (discovery, quotes, verification, Magnet, MCP tools/list)
  oauth2: false
  oidc: false
  mtls: false
  note: 'No OAuth anywhere: /.well-known/oauth-authorization-server, oauth-protected-resource and openid-configuration
    all 404. Identity is a bearer key whose PREFIX names the product that issued it, and on pay-per-call routes
    the credential is the payment itself.'
credential_classes:
- name: Nexus key
  header: 'Authorization: Bearer hm_nexus_…'
  products:
  - Nexus
  - Outcome
  - One
  - Flow
  - AgentOps
  how_to_get: POST https://humanmirror.fr/api/nexus/trial/ (100 free credits, one trial per network origin per 90
    days; 409 if already issued) or Stripe checkout POST /api/nexus/checkout/ then POST /api/nexus/claim/
  spec_schemes:
  - NexusBearer
  - BearerAuth
- name: Forge key
  header: 'Authorization: Bearer hm_forge_…'
  products:
  - Forge
  how_to_get: POST https://humanmirror.fr/api/forge/trial (25 calls) or the 4.99 EUR pack
  spec_schemes:
  - BearerAuth (forge)
- name: Oracle key
  header: 'Authorization: Bearer hm_oracle_…'
  products:
  - Oracle
  how_to_get: 4.99 EUR pack (100 credits) via Stripe
  spec_schemes:
  - ApiKeyBearer
- name: Omni-Sync key
  header: 'Authorization: Bearer hm_omni_…'
  products:
  - Omni-Sync
  - Shared Context Engine (credits first, x402 fallback)
  how_to_get: POST /api/omni-sync/checkout/ (1.99 / 9.99 / 49.99 EUR packs)
  spec_schemes:
  - OmniSyncApiKey
- name: Enterprise Guard key
  header: 'Authorization: Bearer hm_guard_…'
  products:
  - Enterprise Guard preflight (/api/v1/enterprise-guard/preflight/)
  how_to_get: Enterprise Guard subscription (1 500 / 3 000 / 5 000 EUR per month)
  spec_schemes: []
  note: documented on /enterprise-guard/ only; no OpenAPI
- name: HumanMirror Pro key
  header: 'X-API-Key: <key> (README example prefix hm_live_)'
  products:
  - Pro SaaS (/api/v1/saas/*)
  - Next-Gen preview routes (/v1/agent/intent-proof/, /v1/fleet/consensus-lock/, /v1/m2m/escrow-settle/, /v1/agent/state-and-trust/)
    subject to the Pro monthly quota
  how_to_get: HumanMirror Pro subscription, 49 EUR/month (https://humanmirror.fr/dashboard/)
  spec_schemes:
  - HumanMirrorProApiKey
- name: Enterprise Fleet pass
  header: 'Authorization: Bearer <hmep1 token>'
  products:
  - Unlimited Payload Normalizer + Consensus Oracle + Sanitize Shield for 30 days; Next-Gen preview included; referral
    routes
  how_to_get: POST https://humanmirror.fr/api/x402/enterprise-pass/ paying 297 USDC via x402
  spec_schemes:
  - EnterpriseBearer
- name: Genesis allocation token
  header: 'Authorization: Bearer <GENESIS_ALLOCATION_TOKEN>'
  products:
  - POST /api/v1/m2m/resource/ (20 context_compress calls / 48h)
  how_to_get: POST /api/v1/m2m/handshake/ then POST /api/v1/m2m/claim-resource/ (skill.md)
  spec_schemes: []
- name: x402 payment signature
  header: 'PAYMENT-SIGNATURE: <EIP-3009 authorization for the exact USDC amount>'
  products:
  - every /api/x402/* route, /api/v1/m2m/*, /api/v1/consensus/verify/, /api/v1/sanitize/shield/, /api/v1/zero/,
    /api/market/intent|award, /v1/agent/perception-vector/, Agent OS state-and-trust
  how_to_get: Call without it, read the PAYMENT-REQUIRED header on the 402 (x402Version 2, accepts[] amount/payTo/network
    eip155:8453/asset USDC), sign, retry
  observed: '2026-09-19: POST /api/x402/secret-scanning/ -> 402 ''PAYMENT-SIGNATURE header is required'''
  spec_schemes: []
  note: Declared as a header parameter on 68 operations rather than as a securityScheme.
- name: Anonymous
  header: null
  products:
  - MCP initialize/tools/list on all seven servers
  - GET discovery endpoints (/api/v1/sanitize/shield/, /api/v1/m2m/payload-normalizer/, /api/v1/consensus/verify/,
    /api/v1/sink/, /api/v1/zero/, /api/automata, /api/magnet/*, /api/market/live/)
  - POST /api/outcome/quote/, /api/outcome/verify/, /api/flow/quote/, /api/solve/, /api/nexus/search, /api/trace/verify
  how_to_get: nothing
  spec_schemes: []
schemes:
- name: HumanMirrorProApiKey
  type: apiKey
  scheme: null
  in: header
  parameter: X-API-Key
  bearerFormat: null
  description: Active HumanMirror Pro API key. Grants Next-Gen Preview access subject to the Pro monthly API quota.
  source: openapi/humanmirror-fr-x402-openapi.yml
- name: EnterpriseBearer
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: hmep1
  description: Active HumanMirror Enterprise Fleet pass. Next-Gen Preview is included.
  source: openapi/humanmirror-fr-x402-openapi.yml
- name: OmniSyncApiKey
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: hm_omni_*
  description: HumanMirror Omni-Sync API key. One credit per Shared Context operation when credits are available.
  source: openapi/humanmirror-fr-x402-openapi.yml
- name: ApiKeyBearer
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: hm_oracle_…
  description: null
  source: openapi/humanmirror-fr-oracle-openapi.yml
- name: BearerAuth
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: hm_forge_*
  description: null
  source: openapi/humanmirror-fr-forge-openapi.yml
- name: BearerAuth
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: hm_nexus_*
  description: null
  source: openapi/humanmirror-fr-nexus-openapi.yml
- name: NexusBearer
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: hm_nexus_*
  description: null
  source: openapi/humanmirror-fr-agentops-openapi.yml
- name: BearerAuth
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: hm_nexus_*
  description: null
  source: openapi/humanmirror-fr-outcome-openapi.yml
- name: BearerAuth
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: hm_nexus_*
  description: null
  source: openapi/humanmirror-fr-one-openapi.yml
- name: BearerAuth
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: hm_nexus_*
  description: null
  source: openapi/humanmirror-fr-flow-openapi.yml
- name: bearerAuth
  type: http
  scheme: bearer
  in: null
  parameter: null
  bearerFormat: null
  description: null
  source: openapi/humanmirror-fr-physical-oracle-openapi.yml
key_prefix_map:
  hm_nexus_: Nexus / Outcome / One / Flow / AgentOps
  hm_forge_: Forge
  hm_oracle_: Oracle
  hm_omni_: Omni-Sync / Shared Context
  hm_guard_: Enterprise Guard
  hm_live_: Pro (X-API-Key, README example)
  hmep1: Enterprise Fleet pass bearerFormat
privacy_note: The privacy policy states HumanMirror stores a cryptographic digest of the API key, a request id,
  route, tool, hashed IP, status, latency and credits — not raw payloads.
notes:
- 'The derive-authentication.py baseline (method: derived) merged nine differently named bearer schemes into one
  row because they share type/scheme; this searched profile keeps each scheme with its own bearerFormat and source.'
- Keys are never sent as query parameters; every scheme is a header.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/humanmirror-fr-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.