SNHP · Authentication Profile
Snhp Dev Authentication
Authentication
SNHP secures its APIs with apiKey, http-bearer, body-field, and none across 5 declared security schemes, as derived from its OpenAPI definitions.
NegotiationGame TheoryAI AgentsMCPA2AAgentic PaymentsAuctionsMechanism DesignPricing OptimizationArtificial IntelligenceAgent-NativeDeveloper Tools
Methods: apiKey, http-bearer, body-field, none
Schemes: 5
OAuth flows:
API key in: header, header-bearer, body
Security Schemes
BearerKey http
scheme: bearer
XApiKey apiKey
· in: header (X-API-Key)
BodyApiKey apiKey
· in: body (api_key)
MPPPayment http
scheme: Payment
PeerProof custom
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: >-
https://snhp.dev/llms.txt ("Cost model", "Onboarding", "THE STORE — full reference / Auth &
wallet"), https://snhp.dev/.well-known/agents.json (auth block), the operation descriptions of
issue_key_v1_keys_post, rotate_key_v1_keys_rotate_post and store_park_v1_store_park_post in
openapi/snhp-dev-openapi.yml, and live unauthenticated responses on 2026-09-19.
docs: https://snhp.dev/llms.txt
checked: '2026-09-19'
derive_note: >-
0-working/derive-authentication.py produced no profile because the served OpenAPI declares NO
components.securitySchemes and no security[] on any of its 74 operations. The scheme below is
therefore assembled from the provider's prose and its live behaviour, not from the contract —
which is itself a finding: an OpenAPI consumer sees an API with no authentication at all, while
roughly a third of the operations require a key. overlays/ proposes the missing schemes.
summary:
types: [apiKey, http-bearer, body-field, none]
api_key_in: [header, header-bearer, body]
oauth2_flows: []
human_required_to_obtain_key: false
card_required_to_obtain_key: false
self_serve_issuance: 'POST /v1/keys — "Programmatic API key issuance (no human approval)", returns gt_* in <500ms, idempotent on agent_id within 24h, 10 requests/hour per IP.'
key_prefix: gt_
free_surface: 'All Tier 0 math operations (negotiate, bundle, auction.*, mechanism.*, rent/check, helper, notary verify, discovery) work with NO key at the 60/min-per-IP floor.'
schemes:
- name: BearerKey
type: http
scheme: bearer
bearerFormat: 'gt_<opaque>'
header: 'Authorization: Bearer gt_*'
status: documented-not-declared
note: Preferred form. Raises the caller to the 600/min-per-key rate lane; required (or X-API-Key) for the paid store calls when not passing api_key in the body.
- name: XApiKey
type: apiKey
in: header
parameter: X-API-Key
status: documented-not-declared
note: >-
Equivalent to BearerKey. GET /v1/billing/balance with no key answers 422
{"detail":[{"type":"missing","loc":["header","X-API-Key"],"msg":"Field required"}]} — the
header is a declared FastAPI dependency there, and the missing-credential response is a 422
validation error, not a 401, with no WWW-Authenticate.
- name: BodyApiKey
type: apiKey
in: body
parameter: api_key
status: documented-not-declared
note: >-
Several paid operations (SessionOpenIn, SessionMoveIn, ParkIn, FetchIn, CheckoutIn, RotateIn,
StoreRequestIn ...) carry an api_key field in the JSON body and the MCP tools take it as a
tool argument. The provider is explicit that a body key does NOT raise the rate limit
("the limiter only reads headers") and that "header wins" when both are sent. POST
/v1/advice/session with no key answers 422 missing body.api_key.
- name: MPPPayment
type: http
scheme: Payment
header: 'Authorization: Payment <credential carrying a Stripe Shared Payment Token>'
status: documented-and-observed
note: >-
Not identity — a payment credential (Machine Payments Protocol). POST /v1/mpp/topup with no
credential answers 402 application/problem+json with a signed `WWW-Authenticate: Payment
id=..., realm="snhp.dev", method="stripe", intent="charge", request=<b64 challenge>,
description=..., expires=...` header and `Accept-Payment: stripe`; the client authorises the
challenge with an SPT scoped to the store and retries. Observed live 2026-09-19.
- name: PeerProof
type: custom
status: documented
note: >-
The verified-peer A2A flow authenticates OPERATORS, not callers: an Ed25519 keypair per
operator, a signed attestation JWT from POST /v1/registry/register_operator (optionally
upgraded to domain-level by a DNS-TXT challenge), and a short-lived per-negotiation proof
signed locally. Verified server-side by open_session; not a request credential.
key_lifecycle:
issue: 'POST /v1/keys {agent_id, contact_email, intended_use_summary, telemetry_consent?} -> {api_key: gt_*, rate_limit_per_minute: 600, telemetry_consent, wallet (50c starter credit)}'
shown_once: true
rotate: 'POST /v1/keys/rotate — replacement issued, full balance carries over, old key invalidated IMMEDIATELY with no grace period.'
revoke: 'No standalone revoke; rotation is the revocation path.'
recover: 'Manual, human-verified: email the registered contact address from that same address.'
telemetry_consent: 'Set ONCE at issuance and immutable; revoke by DELETE /v1/telemetry/delete + stop passing share_outcome.'
observed:
- {request: 'POST /v1/negotiate/turn (no key, documented quickstart body)', status: 200, note: free floor works}
- {request: 'GET /v1/billing/balance (no key)', status: 422, body: 'missing header X-API-Key'}
- {request: 'POST /v1/advice/session (no key)', status: 422, body: 'missing body api_key'}
- {request: 'POST /v1/mpp/topup (no credential)', status: 402, headers: ['WWW-Authenticate: Payment ...', 'Accept-Payment: stripe']}
see:
scopes: 'none — no OAuth2 (derive-oauth-scopes.py: 0 schemes)'
rate_limits: rate-limits/snhp-dev-rate-limits.yml
conventions: conventions/snhp-dev-conventions.yml
overlay: overlays/snhp-dev-openapi-overlay.yaml
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/snhp-dev-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.