MUJ428 · Authentication Profile
Muj428 Com Authentication
Authentication
MUJ428 declares 0 security scheme(s) across its OpenAPI definitions.
AgentsAgent TrustAgentic CommerceA2AMCPx402PaymentsRisk ManagementVerificationAgent-Native
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/muj428-com-trust-layer-openapi.json
docs:
- https://agents.muj428.com/AGENTS.md
- https://agents.muj428.com/developer.json
- https://agents.muj428.com/index.md
summary:
types: []
api_key_in: []
oauth2_flows: []
bearer: false
credential_classes: 0
headline: >-
No credential of any kind on the read and free-preflight surface. Neither OpenAPI declares a securitySchemes
block or a security requirement (derive-authentication.py found nothing to extract), and the provider says
so in words: "No card. No contract. No signup. No API key. No wallet commitment. No automatic charge."
(index.md); developer.json trust_reflex.auth_required_for_free_calls = false. The only gate on the surface
is ECONOMIC — x402 payment for the five paid services and for Trust Reflex after its free quota — plus one
narrowly scoped bearer token the monitoring endpoint mints. No OAuth, no OIDC, no discovery documents on
any host.
schemes: []
access_model:
free_tier:
what: POST /v1/trust (Trust Reflex), POST /v1/rescue, POST /v1/route, every GET, POST /v1/compatibility*, POST /v1/trust-requests, POST /v1/monitor
credential: none
identity: >-
A caller-chosen stable string, caller_ref (>=3 chars), used only for free-quota accounting (1,000 qualifying
decisions per caller_ref); action_ref is the per-action replay key. No registration binds caller_ref to anyone.
source: OpenAPI TrustAction schema; AGENTS.md "Usage"
paid_tier:
what: POST /v1/evidence-signal, /v1/reputation-check, /v1/milestone-attestation, /v1/trust-layer-report, /v1/transaction-assurance (also under /functions/v1/trust-layer-x402/), and /v1/trust after the free quota
credential: PAYMENT-SIGNATURE request header (x402 v2), caller-supplied
flow:
- POST the request without PAYMENT-SIGNATURE
- receive HTTP 402 and a PAYMENT-REQUIRED header naming exact amount, network (eip155:8453), asset (USDC) and seller
- the caller independently authorizes payment under its own wallet/policy — MUJ428 never fabricates or sends a signature
- retry the same request with a valid PAYMENT-SIGNATURE
- MUJ428 verifies, reserves, settles, fulfils and returns 200 plus PAYMENT-RESPONSE
source: https://agents.muj428.com/developer.json x402_flow; OpenAPI /v1/trust description
note: This is payment, not authentication — it proves the caller paid, not who the caller is.
monitor_token:
what: POST /v1/monitor (201) "response includes a one-time bearer monitor token"
credential: bearer token returned by the create call, scoped to that monitor
source: OpenAPI /v1/monitor 201 description
note: The only bearer credential on the surface; its later use (state/observation updates) is not described in the public spec.
a2a:
what: JSON-RPC at https://agents.muj428.com/a2a
credential: none, but the A2A-Extensions header MUST name https://agents.muj428.com/extensions/trust-reflex/v1 or the endpoint answers -32600
source: live probe 2026-09-19; extension descriptor activation block
mcp:
what: both MCP endpoints
credential: none for initialize / tools/list / free tools; paid tool calls carry payment_signature as a tool argument
source: live tools/list 2026-09-19; invoke_trust_service inputSchema
gateway_headers_observed:
note: >-
The Supabase gateway's CORS allow-list names authorization, apikey and x-client-info — standard Supabase edge-function
headers — alongside payment-signature, x-request-id, idempotency-key and muj428-observer-ref. None of authorization /
apikey is required by any documented MUJ428 operation; do not read the allow-list as an auth scheme.
secrets_policy:
source: https://agents.muj428.com/.well-known/agent-permissions.json
rule: 'MUST NOT send private keys, seed phrases, payment credentials, or other secrets to MUJ428.'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/muj428-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.