WarpPay402 replaces credentials with payment. There is no signup, no API key and no OAuth: an unpaid request to any operation receives HTTP 402 with an x402 v2 challenge, the client signs a USDC transfer for the quoted amount on one of four networks and retries with the signature in a PAYMENT-SIGNATURE header, and the gateway verifies settlement (splitting a platform fee) before proxying the request. The MCP server's discovery methods (initialize, tools/list, resources/list, prompts/list) are fully anonymous; tool calls are settled the same way through the stdio bridge. A flat-rate monthly access token is offered by email but is undocumented, so it is recorded as a claim, not a scheme.
WarpPay402 Studio declares 2 security scheme(s) across its OpenAPI definitions.
generated: '2026-09-19'
method: searched
source: >-
https://www.warppay402.com/ ("No API Keys or Token Management Needed ... they simply send a raw crypto micro-transaction
($0.01–$0.35 USDC) on Base or Solana directly inside the request header. ... Access to our endpoints can also be gained
through traditional API access tokens. Reach out to us ... if interested in a flat rate per month."), the
@warppay402/server README (x402 V2 headers PAYMENT-REQUIRED / PAYMENT-SIGNATURE / PAYMENT-RESPONSE, EIP-712 gasless
TransferWithAuthorization, SPL-USDC, native USDC on Arc), the @warppay402/sdk and @warppay402/mcp-client READMEs
(CUSTOMER_PRIVATE_KEY / WALLETPK), and live 402 responses on https://api.warppay402.com observed 2026-09-19.
derive-authentication.py produced nothing because the provider's OpenAPI declares no securitySchemes.
docs: https://www.warppay402.com/
description: >-
WarpPay402 replaces credentials with payment. There is no signup, no API key and no OAuth: an unpaid request to any
operation receives HTTP 402 with an x402 v2 challenge, the client signs a USDC transfer for the quoted amount on one of
four networks and retries with the signature in a PAYMENT-SIGNATURE header, and the gateway verifies settlement
(splitting a platform fee) before proxying the request. The MCP server's discovery methods (initialize, tools/list,
resources/list, prompts/list) are fully anonymous; tool calls are settled the same way through the stdio bridge. A
flat-rate monthly access token is offered by email but is undocumented, so it is recorded as a claim, not a scheme.
schemes:
- name: x402Payment
type: x402
kind: payment-challenge
in: header
request_header: PAYMENT-SIGNATURE
challenge_header: PAYMENT-REQUIRED
receipt_header: PAYMENT-RESPONSE
challenge_status: 402
version: 2
scheme: exact
applies_to: all 19 REST operations and all 19 MCP tools
networks:
- {caip2: 'eip155:8453', chain: Base, asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913', asset_name: USDC, authorization: EIP-712 TransferWithAuthorization (gasless)}
- {caip2: 'solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp', chain: Solana mainnet-beta, asset: EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v, asset_name: SPL USDC, authorization: signed SPL transfer}
- {caip2: 'eip155:42161', chain: Arbitrum One, asset: '0xaf88d065e77c8cC2239327C5EDb3A432268e5831', asset_name: USDC, authorization: EIP-712 TransferWithAuthorization}
- {caip2: 'eip155:5042', chain: Arc Mainnet, asset: '0x0000000000000000000000000000000000000000', asset_name: native USDC, authorization: direct native value transfer}
challenge_ttl_seconds: 300
amount_units: USDC base units, 6 decimals
client_secret_material: >-
A wallet private key held by the caller (env CUSTOMER_PRIVATE_KEY, alias WALLETPK; CUSTOMER_SOLANA_KEY for Solana in
the SDK). It signs locally and is never transmitted; the privacy policy states the provider "never ask[s] for or
store[s] private keys or seed phrases".
replay_protection: server-side nonce store rejects a reused signature (MemoryNonceStore / RedisNonceStore in @warppay402/server)
evidence:
- {url: 'https://api.warppay402.com/api/v1/tools/web-scraper', method: POST, status: 402, headers: ['payment-required', 'x-payment-required', 'access-control-expose-headers: PAYMENT-REQUIRED, PAYMENT-RESPONSE', 'x-guard-inspected: true']}
- {url: 'https://api.warppay402.com/api/v1/feeds/base-yields', method: GET, status: 402}
- {url: 'https://api.warppay402.com/public_data_feed/index.json', method: GET, status: 402}
- name: flatRateAccessToken
type: apiKey
kind: claimed-undocumented
in: unknown
status: offered by email only
note: >-
Homepage: "Access to our endpoints can also be gained through traditional API access tokens. Reach out to us at
[obfuscated email] if interested in a flat rate per month." Header name, format and issuance are not published and
the OpenAPI declares no scheme, so no agent can use this without a human negotiation.
anonymous_surfaces:
- {url: 'https://api.warppay402.com/mcp', methods: [initialize, tools/list, resources/list, prompts/list], status: 200}
- {url: 'https://api.warppay402.com/openapi.json', status: 200}
- {url: 'https://api.warppay402.com/.well-known/agent.json', status: 200}
- {url: 'https://api.warppay402.com/.well-known/mcp.json', status: 200}
- {url: 'https://api.warppay402.com/.well-known/x402-manifest.json', status: 200}
- {url: 'https://api.warppay402.com/agent-offers.json', status: 200}
- {url: 'https://api.warppay402.com/llms.txt', status: 200}
- {url: 'https://api.warppay402.com/health', status: 200}
oauth2: false
oidc: false
delegated_identity: false
dynamic_client_registration: false
protected_resource_metadata: false
mcp_auth:
discovery: none (anonymous)
invocation: x402 payment signed by the @warppay402/mcp-client bridge from CUSTOMER_PRIVATE_KEY; an unauthenticated tools/call from this crawler returned a JSON-RPC 200 with an empty result object
local_bridge: npx -y @warppay402/mcp-client
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.