generated: '2026-09-19' method: searched source: openapi/agenthealthmonitor-xyz-openapi.yml and openapi/agenthealthmonitor-xyz-verify-openapi.yml (NEITHER declares components.securitySchemes or security[] — derive-authentication.py produced nothing, so this profile is built from the docs and live probes) docs: https://docs.agenthealthmonitor.xyz/#gs-api additional_docs: - https://docs.agenthealthmonitor.xyz/#integration - https://github.com/moonshot-cyber/agent-health-monitor#stripe-fiat--no-wallet-required - https://agenthealthmonitor.xyz/.well-known/x402 - openapi info.description (Payment / Free preview / Coupon access paragraphs) summary: types: - apiKey - x402-payment - internal-key - coupon http_schemes: [] api_key_in: - header oauth2_flows: [] openid_connect: false mutual_tls: false credential_types: - ahm_live_ API key (Stripe credit pack or subscription) - x402 v2 payment proof (X-PAYMENT header) — USDC on eip155:8453 - X-Internal-Key (operator only) - partner coupon code in the URL path public_operations: - api_info_api_info_get - ecosystem_stats_api_ecosystem_stats_get - leaderboard_api_leaderboard_get - get_agent_public_api_agent__address__get - endpoint_info_api_endpoint_info__slug__get - retry_preview_retry_preview__address__get - protection_preview_agent_protect_preview__address__get - alert_status_alerts_status__address__get - configure_alerts_alerts_configure_post - unsubscribe_alerts_alerts_unsubscribe__address__delete - up_up_get - a2a_agent_card__well_known_agent_json_get - x402_discovery__well_known_x402_get - agent_registration__well_known_agent_registration_json_get - create_spec_v1_specs_post (Verify) - get_verdict_v1_verdicts__verdict_id__get (Verify) - health_health_get (Verify) discovery: None of RFC 9728 / RFC 8414 / OIDC. The only machine-readable auth discovery is the x402 402 challenge itself (PAYMENT-REQUIRED header) and /.well-known/x402. dynamic_client_registration: false delegated_identity: false agent_onboarding: Fully autonomous via x402 — an agent with a funded Base wallet needs no account, key or human step; the fiat path needs a human to pay via Stripe and paste the key. schemes: - name: ApiKeyAuth type: apiKey in: header parameter: X-API-Key sources: - https://docs.agenthealthmonitor.xyz/#gs-api - README applies_to: every paid operation as an alternative to x402 (the source lists the X-API-Key bypass paths); required on api_key_status_api_key_status_get and partner_usage_partners__partner_id__usage_get header: 'X-API-Key: ahm_live_' key_format: ahm_live_ prefix (README, SDK examples, source); the docs quick-start shows ahm_sk_… — treat ahm_live_ as authoritative. Keys are credit-metered (Starter 100 / Pro 500 calls) or unlimited on the $99/month subscription; stored server-side and validated per request. issuance: Stripe payment links on https://agenthealthmonitor.xyz/pay-by-card; after checkout the key is retrieved once at GET /stripe/key/{session_id} (retrieve_key_stripe_key__session_id__get). Also via the design-partner programme. rotation: Not documented. No revoke/rotate operation in the API. errors: '401': '{"detail":"X-API-Key header required"} / {"detail":"Invalid or expired API key"}' '429': '{"detail":"API key calls exhausted"}' observed: GET https://agenthealthmonitor.xyz/api/key/status -> 401 {"detail":"X-API-Key header required"} (2026-09-19) - name: X402Payment type: x402 version: 2 in: header parameter: X-PAYMENT (request) / PAYMENT-REQUIRED (402 challenge response) sources: - https://agenthealthmonitor.xyz/.well-known/x402 - live 402 on GET /risk/{address}, GET /ahs/route/policy, POST verify /v1/outputs applies_to: the 15 payable resources in /.well-known/x402 (all 14 documented endpoints plus PUT /ahs/route/policy) and AHM Verify POST /v1/outputs network: eip155:8453 (Base mainnet) asset: USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 (EIP-712 domain name "USD Coin" version "2") scheme: exact pay_to: main_api: '0xaD64EFCe9CfeE4d1D1701d9a0009CCa72B9ff000' ahm_verify: '0x23A2e9Cd7F0a602A3FcFFaf8074113A9205726E5' facilitator: https://facilitator.payai.network max_timeout_seconds: 300 flow: 1) call the endpoint; 2) receive 402 with body {} and PAYMENT-REQUIRED = base64 JSON {x402Version 2, error "Payment required", resource{url, description, mimeType}, accepts[{scheme, network, asset, amount, payTo, maxTimeoutSeconds, extra}], extensions.bazaar}; 3) sign an EIP-3009 transferWithAuthorization for accepts[0]; 4) resend with X-PAYMENT; the facilitator verifies and settles. identity: 'The payer wallet address becomes the caller identity for stateful routes (routing policy owner, batch limits) — "x402 callers: owner_id = lowercased payer wallet" in source.' observed: GET /risk/0x0000000000000000000000000000000000000001 -> 402, accepts[0].amount 1000 (= $0.001); GET /ahs/route/policy -> 402 amount 10000; POST https://verify.agenthealthmonitor.xyz/v1/outputs -> 402 amount 500000 (2026-09-19) - name: InternalKey type: apiKey in: header parameter: X-Internal-Key sources: - 'openapi operation descriptions (Admin tag: "Protected by X-Internal-Key header. Not accessible via x402 payment.")' applies_to: - security_activity_security_activity_get - trust_registry_trust_registry_get - internal_agent_profile_internal_agent_profile__address__get - trigger_acp_scan_acp_scan_trigger_post - acp_scan_status_acp_scan_status_get - trigger_olas_scan_olas_scan_trigger_post - olas_scan_status_olas_scan_status_get - trigger_arc_scan_arc_scan_trigger_post - arc_scan_status_arc_scan_status_get - trigger_celo_scan_celo_scan_trigger_post - celo_scan_status_celo_scan_status_get - trigger_erc8004_scan_erc8004_scan_trigger_post - erc8004_scan_status_erc8004_scan_status_get - erc8183_status_erc8183_status_get note: Operator-only; also bypasses x402 on paid routes (source). Not obtainable by customers. observed: GET /trust-registry -> 401 {"detail":"Unauthorized"} - name: CouponCode type: path-token in: path parameter: '{code} in /coupon/{action}/{code}/{address}' sources: - 'openapi info.description: "partners can use coupon codes to access any paid endpoint without x402 payment"' applies_to: - validate_coupon_coupon_validate__code__get - coupon_risk_coupon_risk__code___address__get - coupon_health_coupon_health__code___address__get - coupon_optimize_coupon_optimize__code___address__get - coupon_retry_coupon_retry__code___address__get - coupon_protect_coupon_protect__code___address__get - coupon_alerts_coupon_alerts__code___address__get - coupon_premium_risk_coupon_risk_premium__code___address__get - coupon_counterparties_coupon_counterparties__code___address__get - coupon_network_map_coupon_network_map__code___address__get - coupon_wash_coupon_wash__code___address__get - coupon_ahs_coupon_ahs__code___address__get - coupon_report_card_coupon_report_card__code___address__get note: Partner-issued codes; rate-limited to 5 attempts per window on validation and access (source). A credential in the URL path, so it appears in logs and caches. agent_card_auth: note: The A2A card (a2a/agenthealthmonitor-xyz-agent-card.json) declares bearerAuth (http bearer, JWT) and an apiKey header named X-AHM-API-Key — neither matches the deployed REST API, which uses X-API-Key and no bearer tokens; the A2A endpoint the card protects is not deployed. sdk: ahm-shield: AHMShield(api_key="ahm_live_...") sends X-API-Key; no x402 support in the SDK (an agent paying with x402 uses an x402 HTTP client instead).