Macaroon Network · Authentication Profile

Macaroonnetwork Com Authentication

Authentication

Public discovery endpoints require no identity. Protected commercial resources use the x402 v2 payment protocol: the client receives HTTP 402 with payment requirements in PAYMENT-REQUIRED, authorises payment according to the advertised scheme, retries with PAYMENT-SIGNATURE and receives PAYMENT-RESPONSE. A verified payment "authorizes only the requested resource transaction. It does not create an account, OAuth session, bearer token, API key, or persistent identity." The payment proof "is not a bearer credential for anything beyond the single call it was issued for -- there is nothing to store, refresh, or revoke."

Macaroon Network secures its APIs with none and x402-payment across 3 declared security schemes, as derived from its OpenAPI definitions.

AgentsAgentic CommerceA2AMCPx402Data MarketplaceComplianceSanctions ScreeningCompany DataScientific ComputingBibleUnited KingdomAgent-Native
Methods: none, x402-payment Schemes: 3 OAuth flows: API key in:

Security Schemes

anonymous none
x402-payment payment
X-Macaroon-Agent-Id header

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://macaroonnetwork.com/auth.md
derived_from: openapi/macaroonnetwork-com-openapi.json
docs:
- https://macaroonnetwork.com/auth.md
- https://api.macaroonnetwork.com/.well-known/oauth-protected-resource
- https://macaroonnetwork.com/listings/vat-validate-v1
- https://macaroonnetwork.com/bible-api
summary:
  types: [none, x402-payment]
  api_key_in: []
  oauth2_flows: []
  oidc: false
  mutual_tls: false
  identity_types_supported: [anonymous]
  note: >-
    The OpenAPI declares no securitySchemes and no security[] on any of its 120 operations, and that is
    accurate rather than an omission: auth.md states "Macaroon Network does not use OAuth registration, user
    accounts, API keys, or bearer credentials for its public pay-per-call services." The mechanical
    derive-authentication.py pass therefore produced no profile; this file is the documented model.
description: >-
  Public discovery endpoints require no identity. Protected commercial resources use the x402 v2 payment
  protocol: the client receives HTTP 402 with payment requirements in PAYMENT-REQUIRED, authorises payment
  according to the advertised scheme, retries with PAYMENT-SIGNATURE and receives PAYMENT-RESPONSE. A verified
  payment "authorizes only the requested resource transaction. It does not create an account, OAuth session,
  bearer token, API key, or persistent identity." The payment proof "is not a bearer credential for anything
  beyond the single call it was issued for -- there is nothing to store, refresh, or revoke."
schemes:
- name: anonymous
  type: none
  applies_to: GET /listings, /listings/search, /listings/{id}, /api/public/*, /api/router/resolve, /api/receipts/{id}, /.well-known/*, /llms.txt, /auth.md, /health, /a2a (JSON-RPC), both MCP servers (initialize, tools/list, free tools), GET /execute/{id} (price preflight)
  sources: [https://macaroonnetwork.com/auth.md, openapi/macaroonnetwork-com-openapi.json]
- name: x402-payment
  type: payment
  protocol: x402
  version: v2
  applies_to: POST /execute/{capability_id} (72 per-capability operations) and paid MCP tool calls (macaroons_execute; macaroons_purchase over L402)
  challenge: 'HTTP 402; header PAYMENT-REQUIRED = base64 JSON {x402Version 2, resource, accepts[{scheme exact, network eip155:8453, amount, asset USDC 0x8335...2913, payTo, maxTimeoutSeconds 60, extra}], extensions.bazaar}; the same JSON is the response body'
  proof: 'header PAYMENT-SIGNATURE = base64 signed payment payload from an x402 v2-compatible wallet (Coinbase CDP or self-managed)'
  receipt: 'header PAYMENT-RESPONSE on the successful paid response; GET /api/receipts/{receipt_id} afterwards'
  optional_headers: ['X-Macaroon-Payment-Rail: x402', 'X-Macaroon-X402-Network: base']
  settlement: exact USDC on Base mainnet, predicate-gated (funds held, settled only if the acceptance predicate passes; failed predicate refunds automatically)
  observed: 'POST https://api.macaroonnetwork.com/execute/vat-validate-v1 -> 402 with PAYMENT-REQUIRED on 2026-09-19'
  sources: [https://macaroonnetwork.com/auth.md, openapi/macaroonnetwork-com-openapi.json (402 responses + x-payment-info), https://macaroonnetwork.com/listings/vat-validate-v1]
- name: X-Macaroon-Agent-Id
  type: header
  purpose: quota scoping only
  description: 'An agent may optionally send a self-assigned X-Macaroon-Agent-Id header purely to scope its own free-tier quota -- this is never an identity or trust credential. Listing free_tier objects call it "self_declared_agent_id_until_account_auth_ships".'
  sources: [https://macaroonnetwork.com/auth.md, https://api.macaroonnetwork.com/.well-known/ai-catalog.json]
oauth:
  implemented: false
  protected_resource_metadata:
    url: https://api.macaroonnetwork.com/.well-known/oauth-protected-resource
    also_on: [https://macaroonnetwork.com/.well-known/oauth-protected-resource, https://www.macaroonnetwork.com/.well-known/oauth-protected-resource]
    resource: https://api.macaroonnetwork.com
    resource_name: Macaroon Network API
    resource_documentation: https://macaroonnetwork.com/auth.md
    bearer_methods_supported: []
    authorization_servers: []
    note: 'auth.md: published "for machine-readable resource discovery, but it intentionally advertises no authorization server." /.well-known/oauth-authorization-server and /.well-known/openid-configuration 404 on every host; no dynamic client registration.'
credentialed_human_surfaces:
- name: Faith Evidence Pro
  url: https://macaroonnetwork.com/bible-api
  note: PayPal subscription ($19/month or $190/year) giving "authenticated REST access to all eleven evidence operations" with "key recovery". The key scheme (header name, issuance) is not documented publicly; not modelled here beyond this note.
- name: Logistics Compliance Pro
  url: https://macaroonnetwork.com/logistics-pro
  note: 'PayPal subscription (£39/month); access is a private lookup link emailed on payment — "No password, no separate account."'
mcp_auth:
  router: none (initialize and tools/list anonymous; paid tools return the x402 challenge)
  bible_evidence: none (free read-only tools; "no API key required for the bounded tools")
a2a_auth:
  note: The agent card declares no securitySchemes; POST /a2a answered JSON-RPC anonymously.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/macaroonnetwork-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.