OptionsAhoy · Authentication Profile
Optionsahoy Com Authentication
Authentication
OptionsAhoy declares 0 security scheme(s) across its OpenAPI definitions.
Equity CompensationTaxStock OptionsFinancial PlanningPersonal FinanceFintechCalculatorsMCPA2AAgent-NativeDeterministicUnited States
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: openapi/optionsahoy-com-openapi.json
docs:
- https://optionsahoy.com/for-agents
- https://github.com/AlvisoOculus/optionsahoy-mcp/blob/main/SECURITY.md
- https://github.com/AlvisoOculus/optionsahoy-mcp/blob/main/llms-install.md
summary:
types: []
api_key_in: []
oauth2_flows: []
bearer: false
credential_classes: 0
headline: >-
No authentication on any surface, by design and by statement. The OpenAPI 3.1.0 contract declares no
securitySchemes and no security requirement; the for-agents page says "No API key, no OAuth"; llms.txt
says "no auth, no install"; the agent card says "OptionsAhoy's API is keyless"; SECURITY.md says "No
accounts, no authentication, no stored user data." The MCP server answers initialize and tools/list
anonymously and serves no OAuth/OIDC discovery documents (/.well-known/oauth-authorization-server,
/.well-known/oauth-protected-resource and /.well-known/openid-configuration all 404). This is a genuine
zero-credential public API, not an undocumented gate: derive-authentication.py correctly produced no
profile, and this file records the absence from the provider's own statements so the auth model reads as
"open" rather than "unknown".
schemes: []
surfaces:
- {surface: REST, endpoint: 'https://optionsahoy.com/api/v1/*', auth: none, evidence: 'OpenAPI has no securitySchemes/security; live GET /api/v1 200 and POST /api/v1/qsbs 400 (validation, not 401) with no credential'}
- {surface: MCP, endpoint: 'https://optionsahoy.com/mcp', auth: none, evidence: 'initialize/tools/list/resources/list/prompts/list all 200 anonymously; no RFC 9728 or RFC 8414 metadata on the host; CORS allows any origin'}
- {surface: A2A, endpoint: 'https://optionsahoy.com/a2a', auth: none, evidence: 'agent card declares no securitySchemes/security; POST message/send with empty params returned a JSON-RPC -32602 validation error, not an auth challenge'}
- {surface: stdio package, install: 'npx -y optionsahoy-mcp', auth: none, evidence: 'llms-install.md: "Requirements: Node 20 or newer. No environment variables are needed."'}
access_controls_that_exist_instead:
- {kind: abuse rate limiting at the edge, evidence: 'privacy policy: a hash of the caller IP is stored so the server can "rate limit abusive traffic without keeping the address itself"; no threshold published (rate-limits/optionsahoy-com-rate-limits.yml)'}
- {kind: license terms, evidence: 'OpenAPI info.license: "Proprietary. Free for non-commercial use during beta." — a legal constraint, not a technical one'}
- {kind: Cloudflare Turnstile, scope: 'the beta-signup and scenario-email FORMS on the website only, per the privacy policy; not the API'}
sessions:
mcp: 'mcp-session-id assigned in the initialize response and echoed by the client (Streamable HTTP); a session handle, not a credential'
mtls: false
signed_requests: false
note: >-
Because nothing authenticates the caller, an agent should treat every response as public data and treat its
own inputs as leaving the user's device (llms.txt: "an agent that calls them is sending inputs over the
network by design"); SECURITY.md states the inputs are not retained.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/optionsahoy-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.