Plyrium · Authentication Profile

Plyrium Com Authentication

Authentication

VouchSpec has no login, API-key signup or OAuth. The read surface is anonymous. The single write operation is gated by PAYMENT, not identity: an x402 v2 challenge-and-retry on POST /api/vouchspec/v1/validate. Credentials exist only AFTER settlement - the 200 response hands back a one-time tenant API key and a one-time delivery token, which together unlock that order's result. The OpenAPI declares no securitySchemes because none of its eight operations takes a credential up front; derive-authentication.py therefore produced no profile and this file is authored from the provider's discovery contract instead.

Plyrium declares 3 security scheme(s) across its OpenAPI definitions.

CompanyAgent SkillsSupply Chain SecuritySoftware Provenancex402Agentic CommerceA2AMCPField ServiceHome Services
Methods: Schemes: 3 OAuth flows: API key in:

Security Schemes

x402-payment payment-gated
scheme: exact
tenant-bearer http
scheme: bearer
delivery-token apiKey
· in: header ()

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://vouchspec.plyrium.com/api/vouchspec/v1/discovery
docs: https://vouchspec.plyrium.com/api/vouchspec/v1/discovery
sources:
- https://vouchspec.plyrium.com/api/vouchspec/v1/discovery (authentication + acquisition + payment blocks)
- https://vouchspec.plyrium.com/openapi.json (no securitySchemes declared; PAYMENT-SIGNATURE header parameter; PaidValidationAccess.credentials schema)
- https://vouchspec.plyrium.com/.well-known/x402 (payTo, facilitator, network)
- https://www.plyrium.com/vouchspec/policies ("Credential handling")
- https://raw.githubusercontent.com/mordiaky/vouchspec/main/docs/payment-flow.md (order/result credential pairing, 30-day delivery capability expiry)
description: >-
  VouchSpec has no login, API-key signup or OAuth. The read surface is anonymous. The single write operation is
  gated by PAYMENT, not identity: an x402 v2 challenge-and-retry on POST /api/vouchspec/v1/validate. Credentials
  exist only AFTER settlement - the 200 response hands back a one-time tenant API key and a one-time delivery
  token, which together unlock that order's result. The OpenAPI declares no securitySchemes because none of its
  eight operations takes a credential up front; derive-authentication.py therefore produced no profile and this
  file is authored from the provider's discovery contract instead.
anonymous_surface:
  operations: [getVouchSpecHealth, getVouchSpecDiscovery, getVouchSpecX402Manifest, getVouchSpecValidationService, getVouchSpecIssuerKey, getVouchSpecReceipt, getVouchSpecReceiptStatus]
  observed: every one answered 200 with no credential on 2026-09-19; response header x-plyrium-auth-bypass anonymous-public
  mcp: https://vouchspec.plyrium.com/api/vouchspec/v1/mcp - tools/list and tools/call anonymous
  a2a: https://vouchspec.plyrium.com/api/vouchspec/v1/a2a - message/send anonymous
schemes:
- name: x402-payment
  type: payment-gated
  applies_to: [purchaseExactCommitValidation]
  protocol: x402
  version: 2
  scheme: exact
  network: eip155:8453 (Base mainnet)
  asset: USDC (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913)
  amount: '0.25'
  atomic_amount: '250000'
  pay_to: '0x5AbA743d6e6Dc22584D9e175D0b39E972AB9918d'
  facilitator: https://api.cdp.coinbase.com/platform/v2/x402
  max_timeout_seconds: 300
  challenge:
    status: 402
    header: PAYMENT-REQUIRED (base64 x402 v2 payment requirements)
    body: JSON with error.code payment_required, accepts[], and an extensions.bazaar block carrying a full example request body
    observed: 2026-09-19 - an empty unpaid POST returned exactly this (documented as the sanctioned challenge-discovery probe)
  retry:
    header: PAYMENT-SIGNATURE (base64 x402 v2 authorization, maxLength 16384, supplied only on the paid retry)
    response_header: PAYMENT-RESPONSE (base64 settlement response on 200)
  registration_required: false
  authentication_before_payment: false
  human_checkout: false
  note: Exact payment retries return the same credentials (discovery acquisition.exact_payment_retries_return_same_credentials true)
- name: tenant-bearer
  type: http
  scheme: bearer
  header: 'Authorization: Bearer {tenant_api_key}'
  issued_by: purchaseExactCommitValidation 200 response (PaidValidationAccess.credentials.tenant_api_key)
  shown_once: true
  stored_as: keyed digest (never plaintext) - policies page "Credential handling"
  applies_to: order and result endpoints returned in PaidValidationAccess.endpoints (order_template, result_template, rotate/revoke delivery-token templates - not in the public OpenAPI)
- name: delivery-token
  type: apiKey
  in: header
  header: X-VouchSpec-Delivery-Token
  issued_by: purchaseExactCommitValidation 200 response (PaidValidationAccess.credentials.delivery_token + delivery_token_expires_at)
  shown_once: true
  expires: yes - delivery_token_expires_at in the response; payment-flow.md states delivery capabilities expire after 30 days and may be rotated or revoked
  applies_to: the same order/result endpoints, REQUIRED TOGETHER with the tenant bearer ("A result requires both credentials")
idempotency_header: 'Idempotency-Key: {unique_8_to_128_character_value}' # documented for authenticated tenant operations; see conventions/
result_authentication:
  media_type: application/vnd.dsse.envelope.v1+json
  signature: Ed25519 over exact DSSE payload bytes
  issuer_key: https://vouchspec.plyrium.com/api/vouchspec/v1/keys/issuer (key_id m3Vz2bX1-lZ-osJb91mHCNE_-Lehx2fFc2TvExDbbn0, RFC 8037 OKP JWK)
  note: The receipt itself is the authenticated object; public receipt bytes need no credential, and the no-store /status endpoint carries live invalidation.
gaps:
- The OpenAPI declares no securitySchemes at all, so a generic client cannot learn from the spec alone that POST /validate is x402-gated; the x-x402 and x-vouchspec extensions and the 402 response carry that information instead.
- The credentialed order/result/rotate/revoke endpoints are named in discovery (route templates) but are absent from the OpenAPI.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/plyrium-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.