ingest0r · Authentication Profile

Ingest0R Com Authentication

Authentication

ingest0r secures its APIs with none and payment across 2 declared security schemes, as derived from its OpenAPI definitions.

CompanyReal EstateProperty RecordsProperty DataPublic RecordsOpen DataGovernment DataGeocodingProperty TaxBuilding PermitsComparable SalesValuationx402Agentic CommerceMCPA2AAgent-NativeChicagoIllinoisLand Parcels
Methods: none, payment Schemes: 2 OAuth flows: API key in:

Security Schemes

none none
x402 payment
scheme: exact · in: header (payment on the retried request) ()

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source:
- https://api.ingest0r.com/openapi.json (x-payment, per-route x-payment-info; no securitySchemes)
- https://api.ingest0r.com/ (discovery manifest "auth" field)
- https://api.ingest0r.com/pricing
- https://api.ingest0r.com/.well-known/x402
- live 402 challenge observed on https://api.ingest0r.com/v1/parcel/{pin}, 2026-09-19
docs:
- https://api.ingest0r.com/llms.txt
spec: openapi/ingest0r-com-openapi.yml
summary:
  types:
  - none
  - payment
  api_key_in: []
  oauth2_flows: []
  bearer: false
  credential_classes: 2
  headline: >-
    No account, no API key, no signup, no wallet to start. The OpenAPI declares no securitySchemes because there
    is no credential: address search and the sample are always free, the three PIN routes return real data free
    for the first 25 calls per client per day, and past that allowance the only "credential" is an x402 v2
    payment — the route answers HTTP 402 with machine-readable terms and is retried with a signed USDC payment on
    Base or Solana. derive-authentication.py therefore produced nothing from the spec; this profile is built from
    the provider's discovery manifest, x402 resource list, pricing endpoint and the live 402 challenge.
schemes:
- name: none
  type: none
  applies_to:
  - v1_search (GET /v1/search/{q}) — always free, unlimited
  - GET /v1/sample — always free, fixed fixture
  - GET /v1/dossier/09253050270000, /09253060510000, /09253140190000 — always-free live example PINs
  - v1_parcel, v1_dossier, v1_comps — first 25 calls per client per day (metered; X-Free-Tier-Remaining header)
  description: >-
    Verbatim from the root manifest: "none — no signup, no API key, and no wallet needed to start: address search
    is always free and the first 25 calls per client per day to the PIN routes return real data free. x402 (USDC)
    covers anything past that."
  observed: >-
    GET /v1/search/1%20E%20113th%20St -> 200 (no headers beyond HSTS); GET /v1/dossier/09253050270000 -> 200 with
    x-free-example: true; GET /v1/parcel/25221090340000 -> 200 with x-free-tier: true, x-free-tier-limit: 25,
    x-free-tier-remaining: 24. The free-tier metering key ("per client") is not documented further.
  sources:
  - https://api.ingest0r.com/
  - https://api.ingest0r.com/pricing
- name: x402
  type: payment
  standard: x402 v2 (HTTP 402)
  in: header (payment on the retried request)
  request_headers: [PAYMENT-SIGNATURE (x402 v2), X-PAYMENT (legacy)]
  response_headers: [PAYMENT-REQUIRED (base64 PaymentRequired), PAYMENT-RESPONSE (settle receipt, per x402 v2)]
  networks:
  - {network: eip155:8453, chain: Base mainnet, asset: USDC, asset_contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913', pay_to: '0x98D530C0667A4B18e692F182DdCAb1c2bECb5B9B'}
  - {network: solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp, chain: Solana mainnet, asset: USDC, asset_mint: EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v, pay_to: G3qr8ahZnuFSYjvrCYM4LLDdoLzFq8Boq9XrURVcA9YF, fee_payer: CjNFTjvBhbJJd2B5ePPMHRLx1ELZpa8dwQgGL727eKww}
  scheme: exact
  facilitator: https://facilitator.payai.network
  max_timeout_seconds: 60
  prices_atomic_usdc_6dp: {v1_search: '0', v1_parcel: '10000', v1_dossier: '30000', v1_comps: '100000'}
  applies_to:
  - v1_parcel ($0.01), v1_dossier ($0.03), v1_comps ($0.10) — past the daily free allowance
  - route-template URLs and directory-probe PINs — always 402 (changelog 0.4.2, "so listing verification is unaffected")
  description: >-
    The OpenAPI carries a top-level x-payment {protocol x402, x402Version 2, accepts[]} and per-operation
    x-payment-info {price {mode fixed, amount, currency USD}, protocols[{x402{...}}]}; the agent card carries the
    same terms as the https://x402.org/extensions/payments capability extension. Payment guards documented in the
    changelog: HEAD never settles, size cap, replay pre-check, and the guards cover both the v2 PAYMENT-SIGNATURE
    header and legacy X-PAYMENT (0.4.1).
  observed: >-
    GET https://api.ingest0r.com/v1/parcel/%7Bpin%7D -> HTTP 402, cache-control private no-store, PAYMENT-REQUIRED
    header present, application/json body with x402Version 2 and both accepts[] entries. Nothing was paid.
  mcp: >-
    On the MCP server the 402 is returned in the tool result as _meta["x402/error"] (isError) and payment is
    supplied via _meta["x402/payment"], with the receipt in _meta["x402/payment-response"] and
    agents-x402/priceUSD in tool _meta (changelog 0.4.1).
  sources:
  - https://api.ingest0r.com/openapi.json
  - https://api.ingest0r.com/.well-known/x402
  - https://api.ingest0r.com/changelog.json

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ingest0r-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.