generated: '2026-09-19' method: searched source: https://agentum.lat/llms.txt additional_docs: - https://agentum.lat/ ("Sem conta, sem chave, sem assinatura: seu agente paga e recebe o resultado na mesma requisição") - https://agentum.lat/openapi.json and https://business.agentum.lat/openapi.json (no securitySchemes, no security requirements; x-payment-info per operation) - https://github.com/orionlabsai/agentum-mcp-server (README + index.js — how the provider's own client authorises a call) - live 402 challenges on both hosts, 2026-09-19 summary: types: [] http_schemes: [] api_key_in: [] oauth2_flows: [] credential_types: [] access_model: payment-gated, credential-less — x402 v2 per-request payment in USDC on Base mainnet stands in for authentication public_operations: [GET https://business.agentum.lat/health, GET https://business.agentum.lat/ (service index), GET /openapi.json on both hosts, GET https://agentum.lat/llms.txt, GET /.well-known/agent-card.json and /.well-known/security.txt] discovery: none — no RFC 8414 authorization-server metadata, no RFC 9728 protected-resource metadata, no OpenID configuration on any host (well-known/agentum-lat-well-known.yml). The machine-readable access contract is the 402 challenge itself. dynamic_client_registration: false delegated_identity: false consent_identity: false schemes: [] payment_gate: protocol: x402 v2 scheme: exact network: eip155:8453 asset: USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 challenge: HTTP 402 with PAYMENT-REQUIRED (base64 JSON PaymentRequirements) on every paid route; maxTimeoutSeconds 300 identity: the payer's on-chain address is the only identity the server sees; there is no account, session, key or token to issue, rotate or revoke pay_to: agentum_lat: '0xB4f9061e3a6A5533431336506b34e1035029599f' business_agentum_lat: '0x7D1EDdfBd167787251fed83b250ABBeA1cf59a6F' gate_order: the payment gate answers before input validation — malformed identifiers (cnpj=123, q=) received a 402, not the contract's 400 reference_client: '@agentum/mcp-server holds the CALLER''s wallet private key in env AGENTUM_MCP_WALLET_KEY and signs with @x402/fetch; the provider never issues or holds a credential' agent_auth: model: wallet-as-principal. An agent needs a funded Base wallet and an x402-capable client; nothing else. No scopes, no consent screen, no delegation — the wallet key IS full authority to spend, which the provider's README treats as the main risk (dedicated wallet, minimal balance, never commit the key). human_in_the_loop: none at the protocol level; the provider's separate @agentum/x402-spend-guard library offers caller-side caps, allowlists and a kill switch a2a_surface: securitySchemes: >- {} (empty) and securityRequirements [] in the agent card; the JSON-RPC root accepted an unauthenticated GetTask (answered -32001 TASK_NOT_FOUND). Whether paid skills are x402-gated over A2A was not observed. notes: - 'No OAuthScopes artifact is emitted: there is no OAuth surface. scopes/ is intentionally absent.' - 'The derive-authentication.py pass produced no profile (0 securitySchemes across both specs), which is correct; this file was written by hand from the provider''s statements and the observed gate.'