generated: '2026-08-09' method: searched source: https://bykaranteli.com/developers docs: https://bykaranteli.com/developers also_searched: - https://bykaranteli.com/api/v1/public/manifest - https://bykaranteli.com/openapi.json - https://mcp.bykaranteli.com summary: >- ByKaranteli runs three distinct access models on one host. The public read surface (/api/public/*, /api/v1/public/*) takes no credential at all. A small account surface (/api/v1/public/me, /api/v1/me/*) takes a Bearer API key owned by a registered member. The paid agent surface (/api/x402/*) takes no account and no key — it authenticates the CALL, not the caller, by settling a USDC micropayment over the x402 protocol. The hosted MCP server at mcp.bykaranteli.com answered an anonymous tools/list, confirming it is unauthenticated. schemes: - id: none type: none applies_to: - /api/public/* - /api/v1/public/* (except /me) - /api/liqmap/public - /embed/* - /feed.xml description: >- No authentication. CORS Access-Control-Allow-Origin is *, GET and OPTIONS preflight are supported, responses are read-only and carry no PII. evidence: 'developers page "Auth · None · All endpoints public / read-only"' - id: bearer_api_key type: http scheme: bearer in: header header: Authorization format: 'Authorization: Bearer ' alternatives: - 'query parameter ?api_key= (for clients that cannot set headers, e.g. calendar feeds)' - 'query parameter ?token=' applies_to: - /api/v1/public/me - /api/v1/me/* requires: member account with public_profile_enabled rate_limit: 60 req/min/key description: >- Member-scoped Bearer token. Same response shape as /api/v1/public/profiles/[handle] but for the key owner. evidence: >- /api/v1/public/manifest -> conventions.auth: "Bearer token in Authorization header, or ?api_key= / ?token= for clients that can't set headers." - id: x402_payment type: payment protocol: x402 version: 2 in: header request_header: X-PAYMENT challenge_header: payment-required challenge_status: 402 applies_to: - /api/x402/* (13 paid endpoints; /api/x402 catalog itself is free) assets: [USDC] networks: - id: 'solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp' chain: Solana mainnet asset_mint: EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v pay_to: 4JgPtoBWkQyG3QffVJC3bfgk7SCQrz9bx2SAEUTSVqzK fee_payer: GVJJ7rdGiXr5xaYbRwRbjfaJL7fmwRygFi1H6aGqDveb - id: 'eip155:8453' chain: Base mainnet asset_contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913' pay_to: '0x0db4c96d8b14f431f3bb8ce1a33f07d2c696a62c' scheme: exact max_timeout_seconds: 300 description: >- Call the endpoint with no payment and it answers HTTP 402 with a base64 `payment-required` header carrying x402 v2 payment requirements — resource URL, service name, tags, accepted networks/assets/amounts, and a `bazaar` extension whose JSON Schema describes the call's input and output shape. An x402 client pays and retries automatically. Price is per SUCCESSFUL response; a failed request settles nothing. No signup on either side. verbatim_challenge: examples/bykaranteli-x402-payment-required.json evidence: url: https://bykaranteli.com/api/x402/flow-vpin http_status: 402 fetched: '2026-08-09' - id: mcp_anonymous type: none applies_to: - https://mcp.bykaranteli.com (Streamable HTTP) description: >- Hosted MCP server requires no key. No OAuth discovery documents are published (/.well-known/oauth-authorization-server and /oauth-protected-resource both 404), consistent with an unauthenticated read-only server. evidence: url: https://mcp.bykaranteli.com method: 'POST tools/list' http_status: 200 result: 20 tools returned anonymously oauth2: false openid_connect: false mutual_tls: false scopes: none notes: - >- There is no OAuth surface, so no scopes/ artifact is emitted — the key-auth member surface carries the model instead. - >- The published OpenAPI (/openapi.json) declares no components.securitySchemes; it marks the free catalog operation `security: []` and leaves the paid operations implicitly gated by the 402 flow. That is the one authentication gap worth raising with the provider — an `x-payment-info` extension is present per operation, but a formal securityScheme is not.