Pictomancer.ai · Authentication Profile
Pictomancer Ai Authentication
Authentication
Pictomancer.ai declares 3 security scheme(s) across its OpenAPI definitions.
CompanyImageImage OptimizationImage ProcessingMediaAgentsMCPA2Ax402MicropaymentsDeveloper Tools
Methods:
Schemes: 3
OAuth flows:
API key in:
Security Schemes
anonymous none
x402 payment
apiKey http
scheme: bearer
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: https://pictomancer.ai/llms.txt (Identity, Pricing, How to connect), https://pictomancer.ai/ (Code and For-agents sections), CORS Access-Control-Allow-Headers on api.pictomancer.ai (Authorization, Content-Type, X-Agent-Wallet, X-Payment), https://pictomancer.ai/.well-known/mcp.json (authentication.required false), agent card x402 extension
docs: https://api.pictomancer.ai/docs
spec_gap: openapi/pictomancer-ai-openapi.yml declares NO securitySchemes and no security requirement; the credential styles below are documented in prose only (captured for the spec in overlays/pictomancer-ai-openapi-overlay.yaml).
summary: >-
Three ways in, all on the same endpoints. (1) Anonymous — the first 50 requests per identity are free with
no account; identity is the X-Agent-Wallet header (an Ethereum address) or, absent that, the caller IP.
(2) x402 pay-per-request — after the free tier the API answers 402 with a USDC price on Base; the agent pays
and retries with X-Payment. No account or key involved. (3) API key — created in the dashboard
(app.pictomancer.ai; login is Google or GitHub OAuth) and sent as Authorization: Bearer; subscription
plans (Dev/Pro/Enterprise) and Stripe top-ups bill against it. The MCP server and A2A endpoint accept the
same identities; /.well-known/mcp.json states authentication.required: false.
schemes:
- name: anonymous
type: none
identity: X-Agent-Wallet header (Ethereum address) or source IP
quota: 50 free requests per identity; analyze and estimate always free
applies_to: REST, MCP, A2A
- name: x402
type: payment
header: X-Payment
protocol: x402 (https://x402.org)
currency: USDC
network: base
flow: request -> 402 with price -> pay -> retry with X-Payment -> 200 (~2s settlement per homepage)
cost_guard: 'Optional X-Max-Cost-USD request header: the API returns 412 instead of charging above the cap; POST /v1/estimate prices a request for free first.'
applies_to: REST, MCP, A2A
- name: apiKey
type: http
scheme: bearer
header: Authorization
format: 'Authorization: Bearer <PICTOMANCER_API_KEY>'
issued_at: https://app.pictomancer.ai (dashboard; create/revoke, usage tracking — changelog v0.3.0)
applies_to: REST, MCP, A2A, WordPress plugin (PICTOMANCER_API_KEY in wp-config.php)
oauth:
api: false
dashboard_login: Google and GitHub OAuth (changelog v0.3.0) — sign-in only, no API scopes, no authorization-server metadata published
key_prefix: not published
rotation: create and revoke keys in the dashboard; no rotation policy published
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pictomancer-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.