generated: '2026-09-19' method: searched source: >- openapi/agent402-dev-openapi.yml (x-payment-client-guidance, x-payment-info, 402 response descriptions, info.x-guidance), https://agent402.dev/api/product (paymentClient, purchaseOptions, purchaseSafety), https://agent402.dev/.well-known/x402 (accepts[]), the homepage "Agent Payment" / "402 Retry Flow" sections and the /site-release-audit buyer-setup page, and live 402 challenges observed 2026-09-20 UTC. docs: https://agent402.dev/site-release-audit checked: '2026-09-19' summary: >- There is no authentication in the credential sense — no accounts, no sign-up, no API keys, no OAuth, no sessions. Access to every paid resource is PAYMENT-AS-AUTHORIZATION under x402 v2: the first request gets HTTP 402 with a PAYMENT-REQUIRED header naming the exact USDC amount on Base (eip155:8453) and the payee; the client signs that authorization and repeats the identical request with a PAYMENT-SIGNATURE header; the server verifies, delivers, and settles. Four support routes are free and anonymous. The OpenAPI declares NO securitySchemes, so derive-authentication.py wrote nothing; this file is the searched profile and overlays/ adds the scheme the contract omits. model: payment-as-authorization (x402 v2, exact scheme, USDC on Base) accounts: none — 'no account' (homepage and product page); 'buyer wallet required' api_keys: none oauth2: none schemes: - name: x402 type: payment protocol: x402 protocol_version: 2 scheme: exact network: eip155:8453 asset: {symbol: USDC, contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913', decimals: 6} pay_to: '0xb0BbF890375B2ea1C2812887aE0331DD82eee92c' request_header: PAYMENT-SIGNATURE response_headers: [PAYMENT-REQUIRED, PAYMENT-RESPONSE] challenge_status: 402 max_timeout_seconds: 300 eip712_domain: {name: USD Coin, version: '2'} # accepts[].extra in the live challenge — the EIP-3009 transferWithAuthorization domain applies_to: ["taskDayPlan", "websitePreflight", "verifiedUrlEvidence", "siteReleaseAudit", "auditX402", "x402Health", "downloadWayfarersDeck", "downloadQrCampaignPack"] free_routes: ["siteReleaseAuditEligibility", "siteReleaseAuditSample", "siteReleaseAuditMethodology", "siteReleaseAuditCaseStudy"] also_free: [/health, /metrics, /pmf/scorecard, /meta.json, /api/product, /openapi.json, /.well-known/x402, /llms.txt] client_requirement_verbatim: 'Use an x402-capable buyer client that validates the pinned terms and supplies PAYMENT-SIGNATURE. Plain curl is a 402 probe only and never pays.' docs: https://agent402.dev/site-release-audit buyer_paths_published: - {path: browser-wallet, detail: 'injected MetaMask or Coinbase Wallet on Base with >= 5 USDC; the page "never receives or stores your private key"; one signed attempt, no automatic retry', url: https://agent402.dev/site-release-audit} - {path: x402-client, detail: 'any x402 v2 client that binds PAYMENT-SIGNATURE to this resource and preserves the eligibility-checked body', url: https://agent402.dev/site-release-audit} - {path: node-recipe, detail: 'npm install --save-exact @payanagent/sdk@0.2.2 @x402/fetch@2.18.0 @x402/evm@2.18.0 viem@2.55.1; WALLET_KEY env var; run once', url: https://agent402.dev/site-release-audit} - {path: payan-marketplace, detail: 'agents-only alternate route, offer kh70zbzh8m5awkegpvn7tc82798aed20 (priceCents 500) at https://payanagent.com/x402/; the provider warns Payan "challenges before seller input validation"', url: https://agent402.dev/api/product} identity_and_delegation: agent_identity: none — no Web Bot Auth, no HTTP Message Signatures, no ERC-8004 reference; the paying wallet is the only identity delegated_identity: none dynamic_client_registration: not applicable (no clients to register) rfc9728_protected_resource_metadata: absent (404) spec_gaps: - 'components.securitySchemes is absent and no operation carries security[], so a generated client sees an open API; the x-payment-client-guidance extension on siteReleaseAudit and x-payment-info on the eight paid operations are where the contract actually states the requirement.'