Liquid Agent · Authentication Profile

Liquidagent Ai Authentication

Authentication

Liquid Agent secures its APIs with apiKey and http across 2 declared security schemes, as derived from its OpenAPI definitions.

Tokenized StocksDeFiInvestingAgentic Commercex402StablecoinsAccount AbstractionGas SponsorshipBaseSolanaAI AgentsAgent-NativeA2APortfolio ManagementMarket Data
Methods: apiKey, http Schemes: 2 OAuth flows: API key in: header

Security Schemes

siwx apiKey
· in: header (SIGN-IN-WITH-X)
x402 http
scheme: x402

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/liquidagent-ai-openapi.yml
docs: https://api.liquidagent.ai/v1/guide
docs_also:
- https://api.liquidagent.ai/llms.txt
- https://api.liquidagent.ai/v1/gas?docs=1
- https://api.liquidagent.ai/.well-known/x402-resources
- https://raw.githubusercontent.com/LiquidAgent/liquidagentx402/main/skills/liquid-gas-sponsor/SKILL.md
summary:
  types: [apiKey, http]
  api_key_in: [header]
  accounts: false
  api_keys_issued: false
  oauth2_flows: []
  model: >-
    No account, no API key, no allowlist. Eleven free operations accept an OPTIONAL wallet identity (SIWX,
    EIP-4361, in a SIGN-IN-WITH-X header) and work anonymously without it - observed live: every free read
    answered 200 with no headers at all. Four paid operations are gated by x402 v2 payment rather than identity:
    the server answers 402 with a PaymentRequired document, the caller signs a USDC authorization for exactly the
    quoted amount and retries with it in an X-PAYMENT (or PAYMENT-SIGNATURE) header. The server holds no key and
    never signs; the caller's own wallet is the only credential anywhere in the system.
schemes:
- name: siwx
  type: apiKey
  in: header
  parameter: SIGN-IN-WITH-X
  description: Sign-In with X wallet identity (EIP-4361). Optional; no payment.
  required: false
  applies_to: [get_v1_guide, get_v1_basket, get_v1_vault_address, get_v1_balance_agent, get_v1_quote, post_v1_create-vault, post_v1_set-weights, post_v1_buy, post_v1_redeem, post_v1_rebalance, post_v1_send]
  observed: All eleven operations answer 200 without the header (probed 2026-09-19), so the scheme is identity, not access control.
  sources: [openapi/liquidagent-ai-openapi.yml]
- name: x402
  type: http
  scheme: x402
  description: Pay-per-call via x402 (exact scheme, EIP-3009 USDC on Base eip155:8453 or Polygon eip155:137). Sign a USDC authorization; no account, no key held by the server.
  required: true
  applies_to: [getV1Signals, postV1Publish, postV1Gas, postV1GasSolana]
  protocol:
    version: 2
    scheme: exact
    challenge: 'HTTP 402; body is the PaymentRequired JSON {x402Version, error, resource, accepts[], extensions}; the same JSON base64-encoded in PAYMENT-REQUIRED and X-PAYMENT-REQUIRED response headers'
    payment_header: X-PAYMENT (PAYMENT-SIGNATURE also accepted on the Solana lane)
    evm_authorization: EIP-3009 transferWithAuthorization on USDC - Base 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, Polygon 0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359; accepts[].extra carries {name USD Coin, version 2, chainId, verifyingContract}
    solana_authorization: one USDC TransferChecked of exactly accepts[].amount to the sponsor's USDC account, sponsor as fee payer, wrapped as {x402Version:2, scheme:exact, network, accepted, payload:{transaction}} and base64d
    payTo: {evm: '0x487b28A4FbbA8Cf46eb6E1d72e6959202Bb75e90', solana: BBcAL97dyJPGmsjQ7pPxCdUsFk1wgZ6jqYQ4DFvCVHkn}
    timeout: maxTimeoutSeconds 60 per accepts[] entry
    erc7677_in_band: On POST /v1/gas JSON-RPC calls HTTP is always 200; an unpaid pm_getPaymasterData returns a JSON-RPC error {code:402, data:<PaymentRequired>} and the payment object goes in params[3].context.x402
    facilitator: PayAI (named in the gas-sponsor SKILL.md)
  sources: [openapi/liquidagent-ai-openapi.yml, https://api.liquidagent.ai/v1/signals (live 402), https://api.liquidagent.ai/v1/gas (live 402)]
signing_is_not_authentication:
  note: >-
    The six transaction builders return unsigned calldata or EIP-712 typed data; the caller signs with the wallet
    that owns the funds and broadcasts to Base itself. That signature authorizes the on-chain action, not the API
    call - the API call needs nothing. Consequently there is nothing to rotate, revoke or leak on the API side.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/liquidagent-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.