KG-NINJA · Authentication Profile
Kgninja Dev Authentication
Authentication
KG-NINJA secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.
AgentsAgentic CommerceA2AMCPx402VerificationJSONCryptographyCloudflare WorkersAgent-NativeJapan
Methods: http
Schemes: 1
OAuth flows:
API key in:
Security Schemes
agentRegistration http
scheme: bearer
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/kgninja-dev-openapi.json
docs: https://agent-economy.kgninja.dev/auth.md
derived_baseline: 'derive-authentication.py 2026-09-19 — 1 scheme (http bearer agentRegistration); upgraded here from the provider''s auth.md and the x402 manifest.'
summary:
types:
- http
model: anonymous-by-design; payment (x402) authorizes the one paid operation per request
api_key_in: []
oauth2_flows: []
oidc: false
credentials_required_for: [GET /agent/registration only]
credentials_not_required_for: [discovery, documentation, health, stats, revenue goal, POST /validate-request, POST /quote, MCP initialize and tools/list, the four free MCP tools, A2A GetTask/ListTasks and the quote-preparation skill]
access_model:
statement: >-
"The verification service is intentionally anonymous: account registration, an API key, OAuth, OpenID
Connect, cookies, and a login session are not required for discovery, quotes, or paid execution."
(auth.md)
oauth_metadata: >-
"OAuth authorization-server and protected-resource metadata are intentionally not published because this
is not an OAuth-protected resource. The optional anonymous registration receipt is not an OAuth access
token." — corroborated: /.well-known/oauth-authorization-server, /.well-known/oauth-protected-resource
and /.well-known/openid-configuration all 404 (well-known/kgninja-dev-well-known.yml).
delegated_identity: none — no authorization_code flow, no user context; the caller is the paying wallet
dynamic_client_registration: none in the RFC 7591 sense; see optional anonymous registration below
schemes:
- name: agentRegistration
type: http
scheme: bearer
bearerFormat: signed anonymous registration receipt
description: Optional 15-minute service-local receipt used only to inspect its own registration claim. It grants no API access and does not authorize payment.
applies_to: [getAnonymousAgentRegistration]
obtained_by: 'POST /agent/register with Content-Type application/json and body {} — no email, account, API key or human contact; the response returns the signed credential once'
credential_type: 'urn:kgninja:params:agent-credential:anonymous-registration-receipt'
lifetime: 15 minutes
revocation: 'none — "There is no revocation endpoint because the receipt has no application privileges and expires after 15 minutes; discard it to stop using it."'
observed: 'GET /agent/registration without a bearer -> 401 {"error":{"code":"AGENT_REGISTRATION_REQUIRED","message":"Provide the short-lived registration credential as Authorization: Bearer <credential>.",...}}'
agent_auth_advertisement: '{"agent_auth":{"skill":"anonymous","register_uri":"https://agent-economy.kgninja.dev/agent/register","identity_types_supported":["anonymous"],"anonymous":{"credential_types_supported":["urn:kgninja:params:agent-credential:anonymous-registration-receipt"],"claim_uri":"https://agent-economy.kgninja.dev/agent/registration"}}}'
sources:
- openapi/kgninja-dev-openapi.json
- https://agent-economy.kgninja.dev/auth.md
payment_authorization:
note: Not a securityScheme in the OpenAPI, but the gate that actually protects the paid operation. Recorded here because an agent choosing a credential strategy needs it next to the auth model.
protocol: x402 v2 (scheme exact)
applies_to: [verifyEvidence, mcp:verify_evidence]
precondition: a free precheck receipt digest (POST /validate-request) inside the unchanged paid intent; otherwise 409 PRECHECK_REQUIRED before any quote or 402
challenge: HTTP 402 with PAYMENT-REQUIRED header + X402PaymentRequired body; over MCP a tool error with _meta["x402/error"]
proof: PAYMENT-SIGNATURE request header (REST) or _meta["x402/payment"] (MCP) on the identical retry
settlement_receipt: PAYMENT-RESPONSE header (REST) or _meta["x402/payment-response"] (MCP)
terms: 10000 atomic USDC on eip155:8453 to 0x4D7d842536De9Eb491AE2300126B3CDdE7B0aDE3, asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, maxTimeoutSeconds 300 (well-known/kgninja-dev-x402.json)
scope_of_the_signature: '"The x402 signature authorizes only the advertised payment and request. It is not a reusable application credential, is independent of optional agent registration, and does not create an authenticated session."'
binding: the signed payload must carry the same binding digest as the bound quote; "A paid retry is accepted only when discovery survived into the paid call and the x402 payload contains the same binding digest."
operator_identity: Cloudflare Wallet handle @kgninja (https://cloudflare.pay/?handle=kgninja) — public identity of the payee, not a credential the caller uses
credential_handling_guidance:
verbatim:
- 'Never send seed phrases, wallet private keys, API secrets, third-party bearer tokens, or unrelated personal data. Send this service''s short-lived registration receipt only to its documented claim endpoint.'
- 'Evidence must be bounded inline JSON. The service does not fetch caller-supplied URLs or execute caller code.'
- 'Verify returned evidence with https://agent-economy.kgninja.dev/.well-known/jwks.json.'
verification_keys:
jwks: https://agent-economy.kgninja.dev/.well-known/jwks.json
file: well-known/kgninja-dev-jwks.json
purpose: 'Verifying the service''s Ed25519 evidence signatures (the service signs; callers verify). Not an authentication credential.'
mcp_registry_proof:
url: https://agent-economy.kgninja.dev/.well-known/mcp-registry-auth
observed: 'v=MCPv1; k=ed25519; p=<public key>'
purpose: domain-ownership proof for MCP Registry publication; public key only
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kgninja-dev-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.