ScalpStream · Authentication Profile

Scalpstream Com Authentication

Authentication

ScalpStream declares 0 security scheme(s) across its OpenAPI definitions.

CompanyAgentsA2Ax402MicropaymentsMCPOpen DataProduct RecallsAir QualityBorder CrossingsFuel PricesMarket ResearchPublic SafetyCryptocurrencyUSDCXRP Ledgerllms-txtJSON Schema
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

scalpstream-com-authentication.yml Raw ↑
generated: '2026-09-19'
method: probed
source: agent cards (securitySchemes/security), /.well-known/x402 documents, live 402 challenges and the marketing site ("no accounts, no API keys, no subscriptions"), 2026-09-19
summary: >-
  There is no authentication. Every surface is anonymous by design: the A2A JSON-RPC endpoints
  and free previews need nothing at all, and the paid HTTP resources are gated by PAYMENT, not
  identity - an x402 v2 challenge (HTTP 402 + PAYMENT-REQUIRED header) that any wallet on one of
  five rails can satisfy per request. No API keys, OAuth, OIDC, mTLS, sign-up or account exist,
  and the agent cards declare securitySchemes {} and security []. The one non-payment gate is a
  required attestation header on the research feed.
schemes: []
schemes_note: no securityScheme of any kind - apiKey, http, oauth2, openIdConnect and mutualTLS are all absent
access_model:
  free:
    surfaces: [GET /preview on every host (+ feed /preview-dividends /preview-crypto /preview-yields /schema), POST /a2a (A2A JSON-RPC), /.well-known/agent-card.json, /.well-known/x402, /llms.txt]
    auth: none
  paid:
    surfaces: [GET /recalls, GET /air, GET /crossings, GET /fuel, GET /picks, GET /dividends, GET /crypto, GET /yields]
    gate: x402 v2 payment challenge (HTTP 402) - see x402/scalpstream-com-x402.yml
    identity_required: false
    payment_header: PAYMENT-REQUIRED (server) / payment payload per x402 v2 (client); legacy X-PAYMENT-REQUIRED also emitted
    rails: [USDC on Base, USDC on Arbitrum, USDC on Polygon, XRP on XRPL, RLUSD on XRPL]
    price_usd: '0.01'
required_headers:
- header: X-Compliance-Attestation
  value: not-sanctioned-party
  applies_to: paid resources on feed.scalpstream.com only
  behaviour: request refused with HTTP 403 before settlement when absent
  source: https://feed.scalpstream.com/.well-known/x402
first_party_client:
  name: scalpmcp (github.com/DV1-321/scalpstream-mcp)
  buyer_secret: EVM_BASE_PRIVATE_KEY held in process memory on the buyer's machine; never sent to ScalpStream
  note: the only key anywhere in the flow is the buyer's own wallet key, per the README
docs: https://www.scalpstream.com/ ("The x402 Flow")

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/scalpstream-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.