SNHP · Authentication Profile

Snhp Dev Authentication

Authentication

SNHP secures its APIs with apiKey, http-bearer, body-field, and none across 5 declared security schemes, as derived from its OpenAPI definitions.

NegotiationGame TheoryAI AgentsMCPA2AAgentic PaymentsAuctionsMechanism DesignPricing OptimizationArtificial IntelligenceAgent-NativeDeveloper Tools
Methods: apiKey, http-bearer, body-field, none Schemes: 5 OAuth flows: API key in: header, header-bearer, body

Security Schemes

BearerKey http
scheme: bearer
XApiKey apiKey
· in: header (X-API-Key)
BodyApiKey apiKey
· in: body (api_key)
MPPPayment http
scheme: Payment
PeerProof custom

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: >-
  https://snhp.dev/llms.txt ("Cost model", "Onboarding", "THE STORE — full reference / Auth &
  wallet"), https://snhp.dev/.well-known/agents.json (auth block), the operation descriptions of
  issue_key_v1_keys_post, rotate_key_v1_keys_rotate_post and store_park_v1_store_park_post in
  openapi/snhp-dev-openapi.yml, and live unauthenticated responses on 2026-09-19.
docs: https://snhp.dev/llms.txt
checked: '2026-09-19'
derive_note: >-
  0-working/derive-authentication.py produced no profile because the served OpenAPI declares NO
  components.securitySchemes and no security[] on any of its 74 operations. The scheme below is
  therefore assembled from the provider's prose and its live behaviour, not from the contract —
  which is itself a finding: an OpenAPI consumer sees an API with no authentication at all, while
  roughly a third of the operations require a key. overlays/ proposes the missing schemes.
summary:
  types: [apiKey, http-bearer, body-field, none]
  api_key_in: [header, header-bearer, body]
  oauth2_flows: []
  human_required_to_obtain_key: false
  card_required_to_obtain_key: false
  self_serve_issuance: 'POST /v1/keys — "Programmatic API key issuance (no human approval)", returns gt_* in <500ms, idempotent on agent_id within 24h, 10 requests/hour per IP.'
  key_prefix: gt_
  free_surface: 'All Tier 0 math operations (negotiate, bundle, auction.*, mechanism.*, rent/check, helper, notary verify, discovery) work with NO key at the 60/min-per-IP floor.'
schemes:
  - name: BearerKey
    type: http
    scheme: bearer
    bearerFormat: 'gt_<opaque>'
    header: 'Authorization: Bearer gt_*'
    status: documented-not-declared
    note: Preferred form. Raises the caller to the 600/min-per-key rate lane; required (or X-API-Key) for the paid store calls when not passing api_key in the body.
  - name: XApiKey
    type: apiKey
    in: header
    parameter: X-API-Key
    status: documented-not-declared
    note: >-
      Equivalent to BearerKey. GET /v1/billing/balance with no key answers 422
      {"detail":[{"type":"missing","loc":["header","X-API-Key"],"msg":"Field required"}]} — the
      header is a declared FastAPI dependency there, and the missing-credential response is a 422
      validation error, not a 401, with no WWW-Authenticate.
  - name: BodyApiKey
    type: apiKey
    in: body
    parameter: api_key
    status: documented-not-declared
    note: >-
      Several paid operations (SessionOpenIn, SessionMoveIn, ParkIn, FetchIn, CheckoutIn, RotateIn,
      StoreRequestIn ...) carry an api_key field in the JSON body and the MCP tools take it as a
      tool argument. The provider is explicit that a body key does NOT raise the rate limit
      ("the limiter only reads headers") and that "header wins" when both are sent. POST
      /v1/advice/session with no key answers 422 missing body.api_key.
  - name: MPPPayment
    type: http
    scheme: Payment
    header: 'Authorization: Payment <credential carrying a Stripe Shared Payment Token>'
    status: documented-and-observed
    note: >-
      Not identity — a payment credential (Machine Payments Protocol). POST /v1/mpp/topup with no
      credential answers 402 application/problem+json with a signed `WWW-Authenticate: Payment
      id=..., realm="snhp.dev", method="stripe", intent="charge", request=<b64 challenge>,
      description=..., expires=...` header and `Accept-Payment: stripe`; the client authorises the
      challenge with an SPT scoped to the store and retries. Observed live 2026-09-19.
  - name: PeerProof
    type: custom
    status: documented
    note: >-
      The verified-peer A2A flow authenticates OPERATORS, not callers: an Ed25519 keypair per
      operator, a signed attestation JWT from POST /v1/registry/register_operator (optionally
      upgraded to domain-level by a DNS-TXT challenge), and a short-lived per-negotiation proof
      signed locally. Verified server-side by open_session; not a request credential.
key_lifecycle:
  issue: 'POST /v1/keys {agent_id, contact_email, intended_use_summary, telemetry_consent?} -> {api_key: gt_*, rate_limit_per_minute: 600, telemetry_consent, wallet (50c starter credit)}'
  shown_once: true
  rotate: 'POST /v1/keys/rotate — replacement issued, full balance carries over, old key invalidated IMMEDIATELY with no grace period.'
  revoke: 'No standalone revoke; rotation is the revocation path.'
  recover: 'Manual, human-verified: email the registered contact address from that same address.'
  telemetry_consent: 'Set ONCE at issuance and immutable; revoke by DELETE /v1/telemetry/delete + stop passing share_outcome.'
observed:
  - {request: 'POST /v1/negotiate/turn (no key, documented quickstart body)', status: 200, note: free floor works}
  - {request: 'GET /v1/billing/balance (no key)', status: 422, body: 'missing header X-API-Key'}
  - {request: 'POST /v1/advice/session (no key)', status: 422, body: 'missing body api_key'}
  - {request: 'POST /v1/mpp/topup (no credential)', status: 402, headers: ['WWW-Authenticate: Payment ...', 'Accept-Payment: stripe']}
see:
  scopes: 'none — no OAuth2 (derive-oauth-scopes.py: 0 schemes)'
  rate_limits: rate-limits/snhp-dev-rate-limits.yml
  conventions: conventions/snhp-dev-conventions.yml
  overlay: overlays/snhp-dev-openapi-overlay.yaml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/snhp-dev-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.