Chado Studio · Authentication Profile

Llama Box Authentication

Authentication

Chado Studio secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.

AgentsA2Ax402DeFiYieldCurve FinancecrvUSDStablecoinsRisk ScoringAnalyticsAgent-Native
Methods: apiKey Schemes: 2 OAuth flows: API key in: header

Security Schemes

X-API-Key (undeclared) apiKey
· in: header (X-API-Key)
x402 payment payment
· in: header (X-PAYMENT (request) / PAYMENT-REQUIRED (challenge response))

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/llama-box-crvusd-yield-optimizer-openapi.yml
docs:
- https://llama.box/yo/docs
- https://llama.box/yo/api/pricing
probed: true
summary:
  types:
  - apiKey
  api_key_in:
  - header
  oauth2_flows: []
  bearer: false
  security_schemes_declared: 0
  headline: >-
    The contract declares NO components.securitySchemes and no security[] requirement — derive-authentication.py
    found nothing to profile — yet six of its ten operations accept an optional X-API-Key header as an ordinary
    parameter, and the live service enforces it: an invalid key returns 401 {"detail":"Invalid API key"}. The
    real gate on the four paid operations is x402 payment (HTTP 402 with a PAYMENT-REQUIRED header, USDC on
    Base Sepolia); the key is the alternative that bypasses it, tied to a "pro or enterprise tier" the
    rebalance operation mentions and nothing publishes. Free operations need neither. No OAuth, no OIDC, no
    bearer tokens, no discovery documents on the host.
schemes:
- name: X-API-Key (undeclared)
  type: apiKey
  in: header
  parameter: X-API-Key
  declared_as: >-
    An optional header PARAMETER (anyOf string|null, required: false) on each operation — not a securityScheme.
    A generator reading securitySchemes sees an unauthenticated API.
  used_by: [list_pools_api_pools_get, best_yield_api_best_yield_get, risk_score_api_risk_score__pool_id__get, simulate_rebalance_api_rebalance_post, a2a_endpoint_a2a_post, a2a_stream_endpoint_a2a_stream_post]
  issuance: >-
    Not published. The simulate_rebalance description says "Requires pro or enterprise tier"; /yo/api/pricing
    lists per-request x402 prices and the contact api@chado.studio but no tier, signup or key-issuance page.
  observed:
  - {request: 'GET https://llama.box/yo/api/best-yield?top=1 with X-API-Key: invalid-probe', status: 401, body: '{"detail":"Invalid API key"}', fetched: '2026-09-19'}
  - {request: 'GET https://llama.box/yo/api/best-yield?top=1 with no key', status: 200, fetched: '2026-09-19', note: free operation}
  - {request: 'POST https://llama.box/yo/api/rebalance with no key', status: 402, body: '{}', fetched: '2026-09-19', note: paid operation — x402 challenge in the PAYMENT-REQUIRED header}
  sources:
  - openapi/llama-box-crvusd-yield-optimizer-openapi.yml
- name: x402 payment
  type: payment
  standard: x402 v2 (HTTP 402 Payment Required)
  in: header
  parameter: X-PAYMENT (request) / PAYMENT-REQUIRED (challenge response)
  description: >-
    Per /yo/api/pricing: "1. Request any paid endpoint without payment -> get 402 with payment details.
    2. Sign a USDC payment on Base using the returned parameters. 3. Resend request with X-PAYMENT header ->
    get 200 with data." The observed challenge is x402Version 2, scheme "exact", network eip155:84532 (Base
    Sepolia testnet), asset 0x036CbD53842c5426634e7929541eC2318f3dCF7e (extra.name USDC, extra.version 2),
    payTo 0x6a1175D0EA0e6817786Ce51F1C4F3294F907f410, maxTimeoutSeconds 300, amount 10000 base units
    ($0.01) for POST /a2a.
  applies_to:
  - {operation: risk_score_api_risk_score__pool_id__get, price: '$0.005'}
  - {operation: simulate_rebalance_api_rebalance_post, price: '$0.01'}
  - {operation: a2a_endpoint_a2a_post, price: '$0.01'}
  - {operation: a2a_stream_endpoint_a2a_stream_post, price: '$0.01'}
  free_operations: [health_health_get, list_pools_api_pools_get, best_yield_api_best_yield_get, pricing_api_pricing_get, agent_card__well_known_agent_json_get, access_log_api_access_log_get]
  note: >-
    Not a securityScheme in the OpenAPI and not declared in the agent card. The paid operations declare only
    200 and 422 responses; the 402 is undocumented in the contract and discoverable only by calling.
  sources:
  - https://llama.box/yo/api/pricing
  - a2a/llama-box-a2a.yml (x-evidence: decoded PAYMENT-REQUIRED header)
discovery_documents:
  openid_configuration: 404
  oauth_authorization_server: 404
  oauth_protected_resource: 404
  note: See well-known/llama-box-well-known.yml.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/llama-box-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.