Pictomancer.ai · Authentication Profile

Pictomancer Ai Authentication

Authentication

Pictomancer.ai declares 3 security scheme(s) across its OpenAPI definitions.

CompanyImageImage OptimizationImage ProcessingMediaAgentsMCPA2Ax402MicropaymentsDeveloper Tools
Methods: Schemes: 3 OAuth flows: API key in:

Security Schemes

anonymous none
x402 payment
apiKey http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://pictomancer.ai/llms.txt (Identity, Pricing, How to connect), https://pictomancer.ai/ (Code and For-agents sections), CORS Access-Control-Allow-Headers on api.pictomancer.ai (Authorization, Content-Type, X-Agent-Wallet, X-Payment), https://pictomancer.ai/.well-known/mcp.json (authentication.required false), agent card x402 extension
docs: https://api.pictomancer.ai/docs
spec_gap: openapi/pictomancer-ai-openapi.yml declares NO securitySchemes and no security requirement; the credential styles below are documented in prose only (captured for the spec in overlays/pictomancer-ai-openapi-overlay.yaml).
summary: >-
  Three ways in, all on the same endpoints. (1) Anonymous — the first 50 requests per identity are free with
  no account; identity is the X-Agent-Wallet header (an Ethereum address) or, absent that, the caller IP.
  (2) x402 pay-per-request — after the free tier the API answers 402 with a USDC price on Base; the agent pays
  and retries with X-Payment. No account or key involved. (3) API key — created in the dashboard
  (app.pictomancer.ai; login is Google or GitHub OAuth) and sent as Authorization: Bearer; subscription
  plans (Dev/Pro/Enterprise) and Stripe top-ups bill against it. The MCP server and A2A endpoint accept the
  same identities; /.well-known/mcp.json states authentication.required: false.
schemes:
- name: anonymous
  type: none
  identity: X-Agent-Wallet header (Ethereum address) or source IP
  quota: 50 free requests per identity; analyze and estimate always free
  applies_to: REST, MCP, A2A
- name: x402
  type: payment
  header: X-Payment
  protocol: x402 (https://x402.org)
  currency: USDC
  network: base
  flow: request -> 402 with price -> pay -> retry with X-Payment -> 200 (~2s settlement per homepage)
  cost_guard: 'Optional X-Max-Cost-USD request header: the API returns 412 instead of charging above the cap; POST /v1/estimate prices a request for free first.'
  applies_to: REST, MCP, A2A
- name: apiKey
  type: http
  scheme: bearer
  header: Authorization
  format: 'Authorization: Bearer <PICTOMANCER_API_KEY>'
  issued_at: https://app.pictomancer.ai (dashboard; create/revoke, usage tracking — changelog v0.3.0)
  applies_to: REST, MCP, A2A, WordPress plugin (PICTOMANCER_API_KEY in wp-config.php)
oauth:
  api: false
  dashboard_login: Google and GitHub OAuth (changelog v0.3.0) — sign-in only, no API scopes, no authorization-server metadata published
key_prefix: not published
rotation: create and revoke keys in the dashboard; no rotation policy published

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pictomancer-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.