MUJ428 · Authentication Profile

Muj428 Com Authentication

Authentication

MUJ428 declares 0 security scheme(s) across its OpenAPI definitions.

AgentsAgent TrustAgentic CommerceA2AMCPx402PaymentsRisk ManagementVerificationAgent-Native
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/muj428-com-trust-layer-openapi.json
docs:
- https://agents.muj428.com/AGENTS.md
- https://agents.muj428.com/developer.json
- https://agents.muj428.com/index.md
summary:
  types: []
  api_key_in: []
  oauth2_flows: []
  bearer: false
  credential_classes: 0
  headline: >-
    No credential of any kind on the read and free-preflight surface. Neither OpenAPI declares a securitySchemes
    block or a security requirement (derive-authentication.py found nothing to extract), and the provider says
    so in words: "No card. No contract. No signup. No API key. No wallet commitment. No automatic charge."
    (index.md); developer.json trust_reflex.auth_required_for_free_calls = false. The only gate on the surface
    is ECONOMIC — x402 payment for the five paid services and for Trust Reflex after its free quota — plus one
    narrowly scoped bearer token the monitoring endpoint mints. No OAuth, no OIDC, no discovery documents on
    any host.
schemes: []
access_model:
  free_tier:
    what: POST /v1/trust (Trust Reflex), POST /v1/rescue, POST /v1/route, every GET, POST /v1/compatibility*, POST /v1/trust-requests, POST /v1/monitor
    credential: none
    identity: >-
      A caller-chosen stable string, caller_ref (>=3 chars), used only for free-quota accounting (1,000 qualifying
      decisions per caller_ref); action_ref is the per-action replay key. No registration binds caller_ref to anyone.
    source: OpenAPI TrustAction schema; AGENTS.md "Usage"
  paid_tier:
    what: POST /v1/evidence-signal, /v1/reputation-check, /v1/milestone-attestation, /v1/trust-layer-report, /v1/transaction-assurance (also under /functions/v1/trust-layer-x402/), and /v1/trust after the free quota
    credential: PAYMENT-SIGNATURE request header (x402 v2), caller-supplied
    flow:
    - POST the request without PAYMENT-SIGNATURE
    - receive HTTP 402 and a PAYMENT-REQUIRED header naming exact amount, network (eip155:8453), asset (USDC) and seller
    - the caller independently authorizes payment under its own wallet/policy — MUJ428 never fabricates or sends a signature
    - retry the same request with a valid PAYMENT-SIGNATURE
    - MUJ428 verifies, reserves, settles, fulfils and returns 200 plus PAYMENT-RESPONSE
    source: https://agents.muj428.com/developer.json x402_flow; OpenAPI /v1/trust description
    note: This is payment, not authentication — it proves the caller paid, not who the caller is.
  monitor_token:
    what: POST /v1/monitor (201) "response includes a one-time bearer monitor token"
    credential: bearer token returned by the create call, scoped to that monitor
    source: OpenAPI /v1/monitor 201 description
    note: The only bearer credential on the surface; its later use (state/observation updates) is not described in the public spec.
  a2a:
    what: JSON-RPC at https://agents.muj428.com/a2a
    credential: none, but the A2A-Extensions header MUST name https://agents.muj428.com/extensions/trust-reflex/v1 or the endpoint answers -32600
    source: live probe 2026-09-19; extension descriptor activation block
  mcp:
    what: both MCP endpoints
    credential: none for initialize / tools/list / free tools; paid tool calls carry payment_signature as a tool argument
    source: live tools/list 2026-09-19; invoke_trust_service inputSchema
gateway_headers_observed:
  note: >-
    The Supabase gateway's CORS allow-list names authorization, apikey and x-client-info — standard Supabase edge-function
    headers — alongside payment-signature, x-request-id, idempotency-key and muj428-observer-ref. None of authorization /
    apikey is required by any documented MUJ428 operation; do not read the allow-list as an auth scheme.
secrets_policy:
  source: https://agents.muj428.com/.well-known/agent-permissions.json
  rule: 'MUST NOT send private keys, seed phrases, payment credentials, or other secrets to MUJ428.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/muj428-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.