Vaultfire Protocol · Authentication Profile

Theloopbreaker Com Authentication

Authentication

Vaultfire Protocol secures its APIs with none, erc-8128-http-signature, x402-payment, and wallet-signature across 5 declared security schemes, as derived from its OpenAPI definitions.

AI AgentsAgent IdentityTrustReputationBlockchainWeb3Paymentsx402MCPA2ACompany
Methods: none, erc-8128-http-signature, x402-payment, wallet-signature Schemes: 5 OAuth flows: API key in:

Security Schemes

publicRead none
erc8128HttpSignature http-message-signature
x402Payment payment
walletSignature self-custody
mcpPrivateKey environment-secret

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
docs: https://theloopbreaker.com/llms.txt
source: >-
  derive-authentication.py found no securitySchemes (components.securitySchemes is {} and no global or
  per-operation security[] in openapi/theloopbreaker-com-openapi.yml). The profile below is therefore from
  the provider's own statements — the OpenAPI info.description ("All endpoints are public and require no
  authentication for reads"), the agent card (authentication.schemes ["none"]; "Write endpoints return
  unsigned transactions for the caller to sign"), ai-plugin.json (auth.type none), SKILL.md ("ERC-8128 —
  signed HTTP requests from agent wallets — request authentication without API keys"), the @vaultfire/mcp-server
  README (PRIVATE_KEY env for write tools) — and from live 2026-09-19 probes.
summary:
  types: [none, erc-8128-http-signature, x402-payment, wallet-signature]
  api_key_in: []
  oauth2_flows: []
  api_keys: false
  oauth2: false
  oidc: false
  mtls: false
schemes:
  - name: publicRead
    type: none
    applies_to: every GET operation in openapi/theloopbreaker-com-openapi.yml and the two free x402 endpoints (/api/x402/trust/health, /api/x402/oracle/chainlink-status)
    evidence: 'GET /api/agent/status?address=0xfA15...813C -> 200 with no credential (2026-09-19)'
  - name: erc8128HttpSignature
    type: http-message-signature
    standard: ERC-8128 (profile of RFC 9421 HTTP Message Signatures, signed by the agent wallet key)
    headers: [Signature, Signature-Input]
    applies_to: routeTask (POST /agent/route) — observed; possibly other write operations, which the spec does not say
    evidence: 'POST /api/agent/route {} -> 401 {"error":"unsigned","reason":"Request is missing ERC-8128 Signature and/or Signature-Input headers"}'
    documented_in_spec: false
  - name: x402Payment
    type: payment
    standard: x402 v2, scheme exact, USDC on Base (eip155:8453)
    headers: [PAYMENT-SIGNATURE (request), PAYMENT-REQUIRED (402 challenge), PAYMENT-RESPONSE (settled response)]
    applies_to: 75 priced endpoints under /api/x402/* (well-known/theloopbreaker-com-x402.json)
    facilitator: https://api.cdp.coinbase.com/platform/v2/x402
    evidence: '402 challenge observed on GET /api/x402/bonds/agent-bond-status and POST /api/x402/actions/accept-bid'
  - name: walletSignature
    type: self-custody
    applies_to: registerAgent, createBond, prepareTask, prepareVKPAction — the API returns an unsigned transaction / contract ABI; state changes happen only when the caller signs and broadcasts with their own wallet
    evidence: OpenAPI response descriptions ("Unsigned transaction to submit on-chain"); agent card authentication.note; Terms section 3 (self-custody)
  - name: mcpPrivateKey
    type: environment-secret
    applies_to: the two write tools of the stdio MCP server (vaultfire_register_agent, vaultfire_create_bond)
    variable: PRIVATE_KEY
    evidence: '@vaultfire/mcp-server README, "Write Tools (require PRIVATE_KEY env var)"'
    note: A wallet private key held by the local process, never sent to Vaultfire.
credential_issuance: none — there is no sign-up, API key or OAuth client; identity is the caller's wallet address
spec_gap: >-
  The contract declares no securitySchemes at all, so the ERC-8128 requirement on routeTask and the x402
  requirement on the priced surface are invisible to a generated client. Captured in
  overlays/theloopbreaker-com-openapi-overlay.yaml.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/theloopbreaker-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.