generated: '2026-09-19' method: searched source: 'openapi/blocklottos-com-openapi.yml (no securitySchemes; POST /api/lottery/agent-referral declares an optional Authorization header parameter with pattern ^Bearer blm_[0-9a-f]{64}$), https://blocklottos.com/api-docs (#ads-overview "No API key required", #lottery-overview "Authentication: None required, all read endpoints are public", #agent-referral challenge/sign flow), /.well-known/ai-plugin.json auth.type none, /.well-known/agent.json trust.no_api_key_for_read_endpoints, live CORS allow-headers 2026-09-19.' docs: https://blocklottos.com/api-docs#agent-referral summary: types: - none - http-bearer - wallet-signature api_key_in: [] oauth2_flows: [] default: none - every read endpoint and every unsigned-transaction builder is public and key-less; access control for money lives in the caller's wallet, not in the API. schemes: - name: public type: none applies_to: all GET operations, buildLotteryTicketTx, submitAd/activate quote and pay steps, getBaseAgentCapabilities, prepareBaseAgentPurchase, confirmBaseTicketPurchase rate_limited: per IP (see rate-limits/) sources: - openapi/blocklottos-com-openapi.yml - https://blocklottos.com/api-docs - name: managementToken type: http scheme: bearer bearerFormat: blm_ + 64 hex chars in: header parameter: Authorization applies_to: getOrCreateUnifiedAffiliateProfile only - payout-wallet changes and private balance/payout-history reads issuance: Returned ONCE when a new affiliate profile is created (or rotated) after a successful ownership proof; "Store the one-time management_token securely". declared_as: an optional header PARAMETER on the operation, not a securityScheme - the contract therefore reports no security at all to tooling sources: - openapi/blocklottos-com-openapi.yml - https://blocklottos.com/api-docs#agent-referral - https://blocklottos.com/llms.txt - name: walletOwnershipChallenge type: wallet-signature flow: - POST /api/lottery/agent-referral {"action":"challenge","primary_chain":"evm","connected_wallet":"0x..."} - sign the exact returned message with the EVM identity wallet (EIP-191 personal_sign, 65-byte hex); the spec also accepts a Solana Ed25519 64-byte hex signature - resubmit with challenge_id (48 hex) + signature applies_to: affiliate enrollment and management-token recovery cost: 0 USDC, no on-chain transaction sources: - openapi/blocklottos-com-openapi.yml - https://blocklottos.com/agents.txt - name: onChainSignature type: wallet-signature note: 'Not API authentication, but the actual authorization for money: the API returns unsigned transactions and the wallet owner signs/broadcasts with eth_sendTransaction; "The Block Lottos server never receives private keys or seed phrases, never signs wallet transactions, and never broadcasts them." (llms.txt)' identification_headers: - name: X-BlockLottos-Agent required: false purpose: optional agent identifier used in the docs curl examples; also carried as agent_id in bodies - name: X-BlockLottos-Intent required: false purpose: listed in Access-Control-Allow-Headers on the agent endpoints; undocumented - name: Idempotency-Key required: false purpose: listed in Access-Control-Allow-Headers on agent-purchase and agent-referral; the documented mechanism is the idempotency_key body field (see conventions/) gaps: - No securitySchemes block, so the Bearer requirement is invisible to generated clients. - No scopes, no OAuth, no API-key issuance - nothing to record in scopes/.