generated: '2026-09-19' method: probed source: live anonymous probes of https://agentcheck.care on 2026-09-19, read against openapi/_original/agentcheck-care-openapi.json docs: https://agentcheck.care/docs spec: openapi/agentcheck-care-openapi.yml summary: types: - apiKey - token-in-path - token-in-query transport: HTTPS only; Cloudflare in front of a FastAPI origin note: >- The served OpenAPI declares NO securitySchemes and NO security requirements on any of its 35 operations, so derive-authentication.py produced nothing. The authentication model below is what the live API told an anonymous caller plus what the operation descriptions say. Most of the surface — tiers, free-scan pool, public stats, validate-bot, start-checkup (free), create-checkout, the A2A endpoint and the agent card — is deliberately anonymous: the product has no login and no account. Three credential-shaped mechanisms exist and none is documented on a page a developer can find. schemes: - name: X-API-Key type: apiKey in: header header: X-API-Key applies_to: - GET /api/credits/balance (credit_balance_api_credits_balance_get) evidence: >- Anonymous GET https://agentcheck.care/api/credits/balance returned HTTP 401, application/json, {"detail":"Missing X-API-Key header"} on 2026-09-19. issuance: undocumented — no page describes how to obtain an API key or what credits are sources: - https://agentcheck.care/api/credits/balance - name: ADMIN_STATS_TOKEN type: apiKey in: unknown applies_to: - GET /api/stats/internal (get_internal_stats_api_stats_internal_get) evidence: >- The operation description says "Requires ADMIN_STATS_TOKEN"; anonymous GET returned HTTP 401 {"error":"Unauthorized"} (a different envelope from the X-API-Key 401). Operator-only; not a developer credential. sources: - openapi/_original/agentcheck-care-openapi.json - name: exam-session-token type: token-in-path in: path parameter: token applies_to: - GET /exam/{token} - GET /exam/{token}/status - POST /exam/{token}/relaunch - POST /exam/{token}/v1/chat/completions evidence: >- The "exam" mode generates a per-checkup secure URL that the customer pastes into their bot as an OpenAI-compatible endpoint (home page step 1; the chat_completions operation description). The token in the path IS the credential. Anonymous GET /exam/nonexistent/status returned 404 {"detail":"Exam session not found"}. sources: - https://agentcheck.care/ - openapi/_original/agentcheck-care-openapi.json - name: report-magic-link type: token-in-query in: query parameters: - token - code applies_to: - GET /report/{checkup_id} (magic_link_report_report__checkup_id__get) evidence: >- "Serve a persisted report via magic link token + optional access code." The privacy policy (3.1) says reports are reachable only via a unique magic link carrying a cryptographic token and tells users to treat the link like a password. Anonymous GET /report/nonexistent returned 404 {"detail":"Report not found"}. sources: - https://agentcheck.care/privacy - openapi/_original/agentcheck-care-openapi.json - name: stripe-webhook type: inbound-webhook applies_to: - POST /api/stripe-webhook (stripe_webhook_api_stripe_webhook_post) note: >- Receiver for Stripe payment events. Signature verification is not described anywhere public and is not asserted here; the endpoint is Stripe-facing, not developer-facing. anonymous_surface: operations: - get_tiers_api_tiers_get - free_scans_endpoint_api_free_scans_get - free_scan_status_api_free_scan_status_get - get_public_stats_api_stats_public_get - health_api_health_get - validate_bot_api_validate_bot_post - start_checkup_api_checkup_post - create_checkout_api_checkout_post - upgrade_checkout_api_checkout_get - a2a_endpoint_a2a_post - agent_card__well_known_agent_card_json_get note: Every one of these answered an anonymous request without a challenge (200, 302 or a 404 on an unknown id). The A2A card declares no securitySchemes, consistent with the open endpoint. customer_credentials_in_requests: note: >- CheckupRequest and CheckoutRequest carry an optional `api_key` field — the CUSTOMER's key for their own bot's chat API, which AgentCheck uses to call the bot under test. The privacy policy (1.3) states it is held in memory for the session only and never written to disk. This is a credential the caller sends, not one AgentCheck issues. gaps: - No securitySchemes in the OpenAPI; a generated client will treat /api/credits/balance as anonymous and get a 401. - No developer page documents the X-API-Key credential or how to obtain one. - No OAuth, no OIDC, no RFC 9728 protected-resource metadata (all /.well-known OAuth paths 404).