Liquid Agent · Authentication Profile
Liquidagent Ai Authentication
Authentication
Liquid Agent secures its APIs with apiKey and http across 2 declared security schemes, as derived from its OpenAPI definitions.
Tokenized StocksDeFiInvestingAgentic Commercex402StablecoinsAccount AbstractionGas SponsorshipBaseSolanaAI AgentsAgent-NativeA2APortfolio ManagementMarket Data
Methods: apiKey, http
Schemes: 2
OAuth flows:
API key in: header
Security Schemes
siwx apiKey
· in: header (SIGN-IN-WITH-X)
x402 http
scheme: x402
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/liquidagent-ai-openapi.yml
docs: https://api.liquidagent.ai/v1/guide
docs_also:
- https://api.liquidagent.ai/llms.txt
- https://api.liquidagent.ai/v1/gas?docs=1
- https://api.liquidagent.ai/.well-known/x402-resources
- https://raw.githubusercontent.com/LiquidAgent/liquidagentx402/main/skills/liquid-gas-sponsor/SKILL.md
summary:
types: [apiKey, http]
api_key_in: [header]
accounts: false
api_keys_issued: false
oauth2_flows: []
model: >-
No account, no API key, no allowlist. Eleven free operations accept an OPTIONAL wallet identity (SIWX,
EIP-4361, in a SIGN-IN-WITH-X header) and work anonymously without it - observed live: every free read
answered 200 with no headers at all. Four paid operations are gated by x402 v2 payment rather than identity:
the server answers 402 with a PaymentRequired document, the caller signs a USDC authorization for exactly the
quoted amount and retries with it in an X-PAYMENT (or PAYMENT-SIGNATURE) header. The server holds no key and
never signs; the caller's own wallet is the only credential anywhere in the system.
schemes:
- name: siwx
type: apiKey
in: header
parameter: SIGN-IN-WITH-X
description: Sign-In with X wallet identity (EIP-4361). Optional; no payment.
required: false
applies_to: [get_v1_guide, get_v1_basket, get_v1_vault_address, get_v1_balance_agent, get_v1_quote, post_v1_create-vault, post_v1_set-weights, post_v1_buy, post_v1_redeem, post_v1_rebalance, post_v1_send]
observed: All eleven operations answer 200 without the header (probed 2026-09-19), so the scheme is identity, not access control.
sources: [openapi/liquidagent-ai-openapi.yml]
- name: x402
type: http
scheme: x402
description: Pay-per-call via x402 (exact scheme, EIP-3009 USDC on Base eip155:8453 or Polygon eip155:137). Sign a USDC authorization; no account, no key held by the server.
required: true
applies_to: [getV1Signals, postV1Publish, postV1Gas, postV1GasSolana]
protocol:
version: 2
scheme: exact
challenge: 'HTTP 402; body is the PaymentRequired JSON {x402Version, error, resource, accepts[], extensions}; the same JSON base64-encoded in PAYMENT-REQUIRED and X-PAYMENT-REQUIRED response headers'
payment_header: X-PAYMENT (PAYMENT-SIGNATURE also accepted on the Solana lane)
evm_authorization: EIP-3009 transferWithAuthorization on USDC - Base 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, Polygon 0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359; accepts[].extra carries {name USD Coin, version 2, chainId, verifyingContract}
solana_authorization: one USDC TransferChecked of exactly accepts[].amount to the sponsor's USDC account, sponsor as fee payer, wrapped as {x402Version:2, scheme:exact, network, accepted, payload:{transaction}} and base64d
payTo: {evm: '0x487b28A4FbbA8Cf46eb6E1d72e6959202Bb75e90', solana: BBcAL97dyJPGmsjQ7pPxCdUsFk1wgZ6jqYQ4DFvCVHkn}
timeout: maxTimeoutSeconds 60 per accepts[] entry
erc7677_in_band: On POST /v1/gas JSON-RPC calls HTTP is always 200; an unpaid pm_getPaymasterData returns a JSON-RPC error {code:402, data:<PaymentRequired>} and the payment object goes in params[3].context.x402
facilitator: PayAI (named in the gas-sponsor SKILL.md)
sources: [openapi/liquidagent-ai-openapi.yml, https://api.liquidagent.ai/v1/signals (live 402), https://api.liquidagent.ai/v1/gas (live 402)]
signing_is_not_authentication:
note: >-
The six transaction builders return unsigned calldata or EIP-712 typed data; the caller signs with the wallet
that owns the funds and broadcasts to Base itself. That signature authorizes the on-chain action, not the API
call - the API call needs nothing. Consequently there is nothing to rotate, revoke or leak on the API side.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/liquidagent-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.