WarpPay402 Studio · Authentication Profile

Warppay402 Com Authentication

Authentication

WarpPay402 replaces credentials with payment. There is no signup, no API key and no OAuth: an unpaid request to any operation receives HTTP 402 with an x402 v2 challenge, the client signs a USDC transfer for the quoted amount on one of four networks and retries with the signature in a PAYMENT-SIGNATURE header, and the gateway verifies settlement (splitting a platform fee) before proxying the request. The MCP server's discovery methods (initialize, tools/list, resources/list, prompts/list) are fully anonymous; tool calls are settled the same way through the stdio bridge. A flat-rate monthly access token is offered by email but is undocumented, so it is recorded as a claim, not a scheme.

WarpPay402 Studio declares 2 security scheme(s) across its OpenAPI definitions.

x402MicropaymentsAI AgentsMCPA2AAgent-NativeWeb ScrapingData ExtractionBlockchainDeFiBaseSolanaSmart ContractsData FeedDeveloper Tools
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

x402Payment x402
scheme: exact · in: header ()
flatRateAccessToken apiKey
· in: unknown ()

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: >-
  https://www.warppay402.com/ ("No API Keys or Token Management Needed ... they simply send a raw crypto micro-transaction
  ($0.01–$0.35 USDC) on Base or Solana directly inside the request header. ... Access to our endpoints can also be gained
  through traditional API access tokens. Reach out to us ... if interested in a flat rate per month."), the
  @warppay402/server README (x402 V2 headers PAYMENT-REQUIRED / PAYMENT-SIGNATURE / PAYMENT-RESPONSE, EIP-712 gasless
  TransferWithAuthorization, SPL-USDC, native USDC on Arc), the @warppay402/sdk and @warppay402/mcp-client READMEs
  (CUSTOMER_PRIVATE_KEY / WALLETPK), and live 402 responses on https://api.warppay402.com observed 2026-09-19.
  derive-authentication.py produced nothing because the provider's OpenAPI declares no securitySchemes.
docs: https://www.warppay402.com/
description: >-
  WarpPay402 replaces credentials with payment. There is no signup, no API key and no OAuth: an unpaid request to any
  operation receives HTTP 402 with an x402 v2 challenge, the client signs a USDC transfer for the quoted amount on one of
  four networks and retries with the signature in a PAYMENT-SIGNATURE header, and the gateway verifies settlement
  (splitting a platform fee) before proxying the request. The MCP server's discovery methods (initialize, tools/list,
  resources/list, prompts/list) are fully anonymous; tool calls are settled the same way through the stdio bridge. A
  flat-rate monthly access token is offered by email but is undocumented, so it is recorded as a claim, not a scheme.
schemes:
- name: x402Payment
  type: x402
  kind: payment-challenge
  in: header
  request_header: PAYMENT-SIGNATURE
  challenge_header: PAYMENT-REQUIRED
  receipt_header: PAYMENT-RESPONSE
  challenge_status: 402
  version: 2
  scheme: exact
  applies_to: all 19 REST operations and all 19 MCP tools
  networks:
  - {caip2: 'eip155:8453', chain: Base, asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913', asset_name: USDC, authorization: EIP-712 TransferWithAuthorization (gasless)}
  - {caip2: 'solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp', chain: Solana mainnet-beta, asset: EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v, asset_name: SPL USDC, authorization: signed SPL transfer}
  - {caip2: 'eip155:42161', chain: Arbitrum One, asset: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831', asset_name: USDC, authorization: EIP-712 TransferWithAuthorization}
  - {caip2: 'eip155:5042', chain: Arc Mainnet, asset: '0x0000000000000000000000000000000000000000', asset_name: native USDC, authorization: direct native value transfer}
  challenge_ttl_seconds: 300
  amount_units: USDC base units, 6 decimals
  client_secret_material: >-
    A wallet private key held by the caller (env CUSTOMER_PRIVATE_KEY, alias WALLETPK; CUSTOMER_SOLANA_KEY for Solana in
    the SDK). It signs locally and is never transmitted; the privacy policy states the provider "never ask[s] for or
    store[s] private keys or seed phrases".
  replay_protection: server-side nonce store rejects a reused signature (MemoryNonceStore / RedisNonceStore in @warppay402/server)
  evidence:
  - {url: 'https://api.warppay402.com/api/v1/tools/web-scraper', method: POST, status: 402, headers: ['payment-required', 'x-payment-required', 'access-control-expose-headers: PAYMENT-REQUIRED, PAYMENT-RESPONSE', 'x-guard-inspected: true']}
  - {url: 'https://api.warppay402.com/api/v1/feeds/base-yields', method: GET, status: 402}
  - {url: 'https://api.warppay402.com/public_data_feed/index.json', method: GET, status: 402}
- name: flatRateAccessToken
  type: apiKey
  kind: claimed-undocumented
  in: unknown
  status: offered by email only
  note: >-
    Homepage: "Access to our endpoints can also be gained through traditional API access tokens. Reach out to us at
    [obfuscated email] if interested in a flat rate per month." Header name, format and issuance are not published and
    the OpenAPI declares no scheme, so no agent can use this without a human negotiation.
anonymous_surfaces:
- {url: 'https://api.warppay402.com/mcp', methods: [initialize, tools/list, resources/list, prompts/list], status: 200}
- {url: 'https://api.warppay402.com/openapi.json', status: 200}
- {url: 'https://api.warppay402.com/.well-known/agent.json', status: 200}
- {url: 'https://api.warppay402.com/.well-known/mcp.json', status: 200}
- {url: 'https://api.warppay402.com/.well-known/x402-manifest.json', status: 200}
- {url: 'https://api.warppay402.com/agent-offers.json', status: 200}
- {url: 'https://api.warppay402.com/llms.txt', status: 200}
- {url: 'https://api.warppay402.com/health', status: 200}
oauth2: false
oidc: false
delegated_identity: false
dynamic_client_registration: false
protected_resource_metadata: false
mcp_auth:
  discovery: none (anonymous)
  invocation: x402 payment signed by the @warppay402/mcp-client bridge from CUSTOMER_PRIVATE_KEY; an unauthenticated tools/call from this crawler returned a JSON-RPC 200 with an empty result object
  local_bridge: npx -y @warppay402/mcp-client

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/warppay402-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.