Hive Civilization · Authentication Profile
Thehiveryiq Com Authentication
Authentication
Hive Civilization secures its APIs with none, x402-payment, apiKey, and ed25519-signed-request across 6 declared security schemes, as derived from its OpenAPI definitions.
AgentsAgentic CommerceA2AMCPx402ReceiptsDigital SignaturePost-Quantum CryptographyAttestationDecentralized IdentityStablecoinsInferenceLLM RoutingComplianceAgent-NativeUnited States
Methods: none, x402-payment, apiKey, ed25519-signed-request
Schemes: 6
OAuth flows:
API key in: header
Security Schemes
none none
x402 payment-challenge
X-Hive-Access apiKey
· in: header (X-Hive-Access)
tenant API key (Bearer) http
scheme: bearer
X-Admin-Api-Key / x-admin-token / X-Hive-Trust apiKey
· in: header ()
DID-signed request signature
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: https://thehiveryiq.com/agents
derived_from:
- openapi/thehiveryiq-com-hivemorph-openapi.yml
- openapi/thehiveryiq-com-hivecompute-openapi.yml
docs:
- https://thehiveryiq.com/agents
- https://thehiveryiq.com/developers
- https://thehiveryiq.com/pricing/
- https://receipts.thehiveryiq.com/llms.txt
- https://receipts.thehiveryiq.com/.well-known/x402.json
summary:
types:
- none
- x402-payment
- apiKey
- ed25519-signed-request
api_key_in:
- header
oauth2_flows: []
openid_connect: false
mutual_tls: false
note: 'NEITHER OpenAPI declares a securitySchemes block and 0 of 937 HiveMorph operations carry a security[] requirement,
so derive-authentication.py has nothing to read: the entire auth model lives in operation descriptions, header
parameters and the docs. Reconstructed from those. The dominant model is ''no credential, pay per call'': discovery
and the free tier need nothing, and paid operations answer HTTP 402 with an x402 payment challenge instead of
401. Tenant API keys (Bearer) exist for the tenant/portal surface; operator-only admin headers appear on a few
dozen internal operations.'
schemes:
- name: none
type: none
applies_to: Discovery documents (/.well-known/*, /openapi.json, /llms.txt, /pricing, /status, /manifest, /a2a
GET), the free tier (POST /v1/receipt/free), receipt verification (POST /v1/receipt/verify, GET /v1/receipt/{receipt_id}),
x402 quotes (POST /v1/x402/quote), GET /v1/settlement/reference, GET /v1/hktn/lookup, POST /v1/delegation/check,
POST /v1/delegation/revoke/{jti}, MCP initialize/tools/list on both MCP hosts, HiveCompute POST /v1/compute/estimate
and GET /v1/compute/models
evidence: 'Observed live 2026-09-19: POST /v1/receipt/free -> 201 with no credential; POST /v1/x402/quote {} ->
200; POST /v1/compute/estimate -> 200; tools/list -> 200 on api.thehiveryiq.com/mcp and hive-mcp-gateway.onrender.com/mcp.
The /agents page: "Verify and quote are always free", "No API key, no signup".'
sources:
- openapi/thehiveryiq-com-hivemorph-openapi.yml
- openapi/thehiveryiq-com-hivecompute-openapi.yml
- name: x402
type: payment-challenge
protocol: x402
applies_to: Every metered operation (receipt emit, rubric select, prospector score, rosetta normalize after the
first 25 free calls per agent, compute.chat, most gateway MCP tools)
challenge:
status: 402
receipts_host:
headers:
x-payment-required: 'true'
body: '{"error":"payment_required","message":"This endpoint requires a micropayment via the x402 protocol.
Submit payment proof via X-Payment header or POST /v1/x402/proof/submit.","payment":{"x402_version":"0.1","nonce":"<uuid>","resource":"/v1/receipt/emit","amount_usd":0.0008,"payment_endpoint":"/v1/x402/proof/submit","expires_at":<unix>,"accepts":[{"chain":"base","asset":"USDC","scheme":"exact","recipient":"0x15184bf5...436e","asset_contract":"0x833589fC...02913","decimals":6,"amount_atomic":"800"},
...USDT/base, USDC+USDT/solana, USDT/ethereum]}}'
observed: POST /v1/receipt/emit without payment, 2026-09-19
hivecompute_host:
headers:
www-authenticate: x402
payment-required: '<base64url JSON: {"x402Version":1,"accepts":[{"scheme":"exact","network":"base","maxAmountRequired":"20000","resource":"https://api.thehiveryiq.com/v1/compute/chat/completions","payTo":"0x15184Bf5...436E","maxTimeoutSeconds":300,"asset":"0x833589fC...02913","extra":{"name":"USD
Coin","version":"2","assetTransferMethod":"eip3009"}}]}>'
observed: POST /v1/compute/chat/completions without payment, 2026-09-19
note: 'The two hosts speak two different x402 envelope generations (x402_version 0.1 JSON body vs x402Version
1 base64 PAYMENT-REQUIRED header + www-authenticate: x402).'
settlement:
submit: 'POST /v1/x402/proof/submit (operationId submit_proof_v1_x402_proof_submit_post): "Submit a payment
proof for a pending 402 nonce. On success, returns an access token (5-minute TTL) that can be used in the
X-Hive-Access header to bypass 402 for the same path."'
header_alternative: X-Payment header carrying the proof
rails: 'https://receipts.thehiveryiq.com/v1/x402/rails and /.well-known/x402.json: USDC + USDT on Base (8453),
USDC + USDT on Solana, USDT on Ethereum; scheme exact; EIP-3009 transferWithAuthorization on Base'
client_sdk: hive-rosetta (npm/PyPI 0.1.0) implements the 402 -> sign -> retry loop
sources:
- openapi/thehiveryiq-com-hivemorph-openapi.yml
- openapi/thehiveryiq-com-hivecompute-openapi.yml
- https://receipts.thehiveryiq.com/.well-known/x402.json
- name: X-Hive-Access
type: apiKey
in: header
parameter: X-Hive-Access
applies_to: Short-lived (5-minute) access token minted by /v1/x402/proof/submit for the paid path; also a header
parameter on POST /v1/activation/keys
sources:
- openapi/thehiveryiq-com-hivemorph-openapi.yml
- name: tenant API key (Bearer)
type: http
scheme: bearer
key_prefix: tk_live_
applies_to: 'Tenant / portal surface: POST /tenants/:id/receipts (documented on /developers as the "authenticated
tenant route"), GET /tenants/:id/evidence, wallet (/v1/wallet/register, /v1/wallet/me), designer mint, bounty
admin; the pricing page lists "API key auth via Bearer header" on the Builder tier'
evidence: 'POST /v1/portal/{tenant_id}/api-key/revoke description: ''Pass { "key": "tk_live_..." } to revoke a
specific key; omit to revoke all.'' The ''authorization'' header parameter is declared on 8 operations.'
issuance: Tenant onboarding wizard at https://thehiveryiq.com/onboard/ ; keys revocable via portal_revoke_key_v1_portal__tenant_id__api_key_revoke_post
sources:
- openapi/thehiveryiq-com-hivemorph-openapi.yml
- https://thehiveryiq.com/pricing/
- name: X-Admin-Api-Key / x-admin-token / X-Hive-Trust
type: apiKey
in: header
parameters:
- X-Admin-Api-Key
- x-admin-token
- X-Hive-Trust
applies_to: 'Operator-only operations (x402 pricing/rails admin, evaluator start/stop, perp liquidation, dashboards,
site-traffic redaction): 34 header parameters across ~20 operations'
note: Not customer credentials; recorded so an agent does not mistake these operations for callable surface.
sources:
- openapi/thehiveryiq-com-hivemorph-openapi.yml
- name: DID-signed request
type: signature
headers:
- x-hive-nonce
- x-hive-sig
algorithm: Ed25519
applies_to: 'POST /v1/mos/intel/register: "site-did + x-hive-nonce + x-hive-sig (ed25519)" per its description;
agent identity elsewhere is carried as agent_did (did:hive:...) in request bodies without signature'
sources:
- openapi/thehiveryiq-com-hivemorph-openapi.yml
response_provenance:
note: 'Authentication of the SERVER to the client is a first-class feature: api.thehiveryiq.com signs every response
(X-Hive-Prov-Iss did:hive:hivecompute, X-Hive-Prov-Ts, X-Hive-Prov-Sig, X-Hive-Prov-Pubkey -> /v1/prov/pubkey,
X-Hive-Prov-Payload) and publishes a JWKS; receipts.thehiveryiq.com publishes its Ed25519 verifier key at /v1/prov/pubkey
and /trust.json (issuer did:hive:hivemorph, epoch 1, rotation "on-incident or annual"); passport.thehiveryiq.com
does the same for did:hive:hive-passport.'
observed: Response headers on GET https://api.thehiveryiq.com/openapi.json, 2026-09-19
gaps:
- No securitySchemes in either OpenAPI, so generated clients cannot attach credentials or model the 402 flow.
- No OAuth 2.0 / OIDC anywhere (RFC 8414 / 9728 / OIDC discovery all absent on every host, including both MCP hosts).
- 'Key lifecycle: no documented rotation for tenant keys; the security page states "no verified 90-day automatic
invalidation policy".'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/thehiveryiq-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.