Sirenic · Authentication Profile

Sirenic Eu Authentication

Authentication

Sirenic secures its APIs with x402 payment (no credential), apiKey, http bearer, and oauth2 (MCP connector only) across 4 declared security schemes, as derived from its OpenAPI definitions.

Company DataBusiness RegistryKYBSanctions ScreeningFinancial DataCredit RiskVAT ValidationIBAN ValidationE-InvoicingPublic ProcurementOpen DataFranceEuropex402Agentic CommerceMCPA2ACompany
Methods: x402 payment (no credential), apiKey, http bearer, oauth2 (MCP connector only) Schemes: 4 OAuth flows: API key in: header

Security Schemes

ApiKeyAuth apiKey
· in: header (X-Api-Key)
BearerAuth http
scheme: bearer
McpConnectorOAuth oauth2
· flows:
X402Payment x402
· in: header (PAYMENT-SIGNATURE)

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/sirenic-eu-openapi.yml securitySchemes, enriched from llms.txt ("PAY WITH AN API KEY INSTEAD OF
  x402"), the RFC 8414/9728 discovery documents and the privacy policy MCP-connector section.
summary:
  types:
  - x402 payment (no credential)
  - apiKey
  - http bearer
  - oauth2 (MCP connector only)
  api_key_in:
  - header
schemes:
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter: X-Api-Key
  description: 'Sirenic API key (srn_live_…) paying with prepaid credits (1 credit = 1 EUR, same prices as x402).
    Credits expire 12 months after purchase; calls are charged first to the credits closest to expiry. Optional:
    without it, the same routes answer 402 with a signable x402 quote. Insufficient balance → 402 {error: credits_insuffisants}
    WITHOUT a PAYMENT-REQUIRED header. Get a key at /compte.'
  sources:
  - openapi/sirenic-eu-openapi.yml
- name: BearerAuth
  type: http
  scheme: bearer
  description: 'The same srn_live_… API key sent as Authorization: Bearer. A bearer value that is not an srn_ key
    is ignored (x402 flow unchanged).'
  sources:
  - openapi/sirenic-eu-openapi.yml
- name: McpConnectorOAuth
  type: oauth2
  applies_to: https://api.sirenic.eu/mcp/connecteur (MCP over OAuth, for assistants) — not the REST API
  flows:
    authorizationCode:
      authorizationUrl: https://api.sirenic.eu/compte/connecteur
      tokenUrl: https://api.sirenic.eu/oauth/jeton
      refreshUrl: https://api.sirenic.eu/oauth/jeton
      scopes:
        mcp: call the data routes on behalf of the account holder
  pkce: S256 required
  dynamic_client_registration: https://api.sirenic.eu/oauth/enregistrement (RFC 7591) + client_id_metadata_document_supported
  sources:
  - well-known/sirenic-eu-oauth-authorization-server.json
  - well-known/sirenic-eu-oauth-protected-resource.json
- name: X402Payment
  type: x402
  in: header
  parameter: PAYMENT-SIGNATURE
  description: 'x402 v2 (kind resource-server) — discovery document at /.well-known/x402 lists every priced resource
    with its accepts[] (scheme exact, network eip155:8453, asset USDC 0x8335…2913 or EURC 0x60a3…db42, payTo 0x76A672EEe56D29D475b0715cc03B8C99D70EC8A2,
    maxTimeoutSeconds 120). Not an authentication scheme in the OpenAPI sense (security: [{}] allows anonymous),
    but it is the default access rail.'
  sources:
  - well-known/sirenic-eu-x402.json
  - llms/sirenic-eu-llms.txt
docs:
- https://api.sirenic.eu/llms.txt
- https://api.sirenic.eu/openapi.json
- https://api.sirenic.eu/.well-known/oauth-authorization-server
- https://api.sirenic.eu/confidentialite
access_model:
  default: No credential. Any /v1 GET without payment answers 402 with an x402 v2 quote (body + PAYMENT-REQUIRED
    header); the client signs it (USDC or EURC on Base, eip155:8453) and retries with PAYMENT-SIGNATURE. Non-2xx
    responses are never settled.
  api_key: 'X-Api-Key: srn_live_… or Authorization: Bearer srn_live_… — prepaid credits (1 credit = 1 EUR, packs
    10/20/50/100 EUR, valid 12 months, closest-to-expiry spent first). Response carries X-Credits-Charged and X-Credits-Remaining.
    Insufficient balance → 402 {error: credits_insuffisants} without an x402 quote. A signed x402 payment takes
    precedence over a key.'
  free_tier: '150 calls/month on routes priced ≤ $0.05 with a verified account (llms.txt / mcp.json). Free routes
    need nothing: /v1/suggestions, /v1/reperer, /v1/lecture, /v1/provenance/registres, /v1/demo/entreprise, /preview/…,
    /healthz.'
  account_gated: GET /v1/documents/{type}/{id} with type=actes requires an identified account (401 otherwise) since
    2026-09-19 — legal deeds carry personal data.
  key_storage: Keys and tokens are stored only as SHA-256 fingerprints; the customer area uses magic-link e-mail
    login, no password (privacy policy, Sécurité).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/sirenic-eu-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.