Chado Studio · Authentication Profile
Llama Box Authentication
Authentication
Chado Studio secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.
AgentsA2Ax402DeFiYieldCurve FinancecrvUSDStablecoinsRisk ScoringAnalyticsAgent-Native
Methods: apiKey
Schemes: 2
OAuth flows:
API key in: header
Security Schemes
X-API-Key (undeclared) apiKey
· in: header (X-API-Key)
x402 payment payment
· in: header (X-PAYMENT (request) / PAYMENT-REQUIRED (challenge response))
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/llama-box-crvusd-yield-optimizer-openapi.yml
docs:
- https://llama.box/yo/docs
- https://llama.box/yo/api/pricing
probed: true
summary:
types:
- apiKey
api_key_in:
- header
oauth2_flows: []
bearer: false
security_schemes_declared: 0
headline: >-
The contract declares NO components.securitySchemes and no security[] requirement — derive-authentication.py
found nothing to profile — yet six of its ten operations accept an optional X-API-Key header as an ordinary
parameter, and the live service enforces it: an invalid key returns 401 {"detail":"Invalid API key"}. The
real gate on the four paid operations is x402 payment (HTTP 402 with a PAYMENT-REQUIRED header, USDC on
Base Sepolia); the key is the alternative that bypasses it, tied to a "pro or enterprise tier" the
rebalance operation mentions and nothing publishes. Free operations need neither. No OAuth, no OIDC, no
bearer tokens, no discovery documents on the host.
schemes:
- name: X-API-Key (undeclared)
type: apiKey
in: header
parameter: X-API-Key
declared_as: >-
An optional header PARAMETER (anyOf string|null, required: false) on each operation — not a securityScheme.
A generator reading securitySchemes sees an unauthenticated API.
used_by: [list_pools_api_pools_get, best_yield_api_best_yield_get, risk_score_api_risk_score__pool_id__get, simulate_rebalance_api_rebalance_post, a2a_endpoint_a2a_post, a2a_stream_endpoint_a2a_stream_post]
issuance: >-
Not published. The simulate_rebalance description says "Requires pro or enterprise tier"; /yo/api/pricing
lists per-request x402 prices and the contact api@chado.studio but no tier, signup or key-issuance page.
observed:
- {request: 'GET https://llama.box/yo/api/best-yield?top=1 with X-API-Key: invalid-probe', status: 401, body: '{"detail":"Invalid API key"}', fetched: '2026-09-19'}
- {request: 'GET https://llama.box/yo/api/best-yield?top=1 with no key', status: 200, fetched: '2026-09-19', note: free operation}
- {request: 'POST https://llama.box/yo/api/rebalance with no key', status: 402, body: '{}', fetched: '2026-09-19', note: paid operation — x402 challenge in the PAYMENT-REQUIRED header}
sources:
- openapi/llama-box-crvusd-yield-optimizer-openapi.yml
- name: x402 payment
type: payment
standard: x402 v2 (HTTP 402 Payment Required)
in: header
parameter: X-PAYMENT (request) / PAYMENT-REQUIRED (challenge response)
description: >-
Per /yo/api/pricing: "1. Request any paid endpoint without payment -> get 402 with payment details.
2. Sign a USDC payment on Base using the returned parameters. 3. Resend request with X-PAYMENT header ->
get 200 with data." The observed challenge is x402Version 2, scheme "exact", network eip155:84532 (Base
Sepolia testnet), asset 0x036CbD53842c5426634e7929541eC2318f3dCF7e (extra.name USDC, extra.version 2),
payTo 0x6a1175D0EA0e6817786Ce51F1C4F3294F907f410, maxTimeoutSeconds 300, amount 10000 base units
($0.01) for POST /a2a.
applies_to:
- {operation: risk_score_api_risk_score__pool_id__get, price: '$0.005'}
- {operation: simulate_rebalance_api_rebalance_post, price: '$0.01'}
- {operation: a2a_endpoint_a2a_post, price: '$0.01'}
- {operation: a2a_stream_endpoint_a2a_stream_post, price: '$0.01'}
free_operations: [health_health_get, list_pools_api_pools_get, best_yield_api_best_yield_get, pricing_api_pricing_get, agent_card__well_known_agent_json_get, access_log_api_access_log_get]
note: >-
Not a securityScheme in the OpenAPI and not declared in the agent card. The paid operations declare only
200 and 422 responses; the 402 is undocumented in the contract and discoverable only by calling.
sources:
- https://llama.box/yo/api/pricing
- a2a/llama-box-a2a.yml (x-evidence: decoded PAYMENT-REQUIRED header)
discovery_documents:
openid_configuration: 404
oauth_authorization_server: 404
oauth_protected_resource: 404
note: See well-known/llama-box-well-known.yml.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/llama-box-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.