Kimetsu Dev Authentication
The Agent Gateway is anonymous by contract and by enforcement: the OpenAPI declares no securitySchemes and an empty security[] on every operation, the directory says "Never send credentials, cookies, private data, or authorization headers. They are rejected", and a GET carrying "Authorization: Bearer test" was answered 400 {"error":"credentials_rejected"}. derive-authentication.py therefore produced no profile (0 schemes); this file records the observed policy instead. The only authenticated surface in the product family is the self-hosted Kimetsu Remote server, which is operator-run and outside the gateway.
Kimetsu secures its APIs with none across 0 declared security schemes, as derived from its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.