generated: '2026-09-19' method: probed source: securitySchemes on https://bianhuakai.club/.well-known/agent.json + an anonymous POST to https://bianhuakai.club/a2a/, 2026-09-19 summary: >- The A2A JSON-RPC endpoint is anonymous. The agent card declares securitySchemes {} and no security[] requirement, and a POST with no Authorization header was answered with a JSON-RPC envelope (HTTP 200), so no credential of any kind gates the agent surface. The consumer chat app at the site root and the "Chat with me" widget on /lei/ use an email + verification-code login (client-side calls to /auth/register, /auth/verify, /auth/login, /auth/forgot, /auth/reset) - a human account system for the web UI, not a developer credential, and not documented as an API. There is no OAuth, no OIDC discovery, no API keys and no developer signup. schemes: [] scheme_count: 0 agent_surface: endpoint: https://bianhuakai.club/a2a/ auth: none evidence: "card securitySchemes is {}; anonymous POST answered 200 with a JSON-RPC error envelope (-32601 for an unknown method)" cors_allowed_headers: [Content-Type, Authorization, x-broker-token] cors_note: "the CORS allow-list names Authorization and x-broker-token, so the server is prepared to receive them, but nothing published requires either" oauth: false openid_configuration_status: 404 oauth_authorization_server_status: 404 oauth_protected_resource_status: 404 docs: null docs_note: no authentication documentation is published