generated: '2026-09-19' method: searched source: openapi/cymetica-com-eventtrader-public-api-openapi.yml summary: types: - apiKey - http - oauth2 api_key_in: - header oauth2_flows: - authorizationCode docs_upgrade: 'Three documented ways in: (1) register + POST /auth/api-key under a JWT, (2) one-call bootstrap POST /auth/api-key with email+password, (3) POST /mcp/v1/register for an instant mcp_ agent key. Plus OAuth 2.0 authorization-code with PKCE S256 (RFC 8414 + RFC 9728 discovery, RFC 7591 registration) whose tokens work on REST but not on /mcp/v1, and SIWE wallet sign-in via the Python SDK. A 401 carries WWW-Authenticate: Bearer and {"detail": "Authentication required. Provide Bearer token or X-API-Key header."}.' schemes: - name: ApiKeyAuth type: apiKey in: header parameter: X-API-Key sources: - openapi/cymetica-com-eventtrader-public-api-openapi.yml key_prefixes: user: evt_ agent: mcp_ issuance: - POST /auth/api-key (JWT or email+password bootstrap) -> api_key + api_secret - POST /api/v1/api-keys (session JWT only) -> named key with permissions {read, trade, withdraw} - POST /mcp/v1/register (no auth) -> mcp_ key, trust_level recognized permissions: - read - trade - withdraw (registered agent keys only; user keys and OAuth tokens cannot withdraw) storage: SHA-256 hashed; plaintext shown once - name: BearerJWT type: http scheme: bearer bearerFormat: JWT description: Account session JWT (from /auth/login). Key-management routes accept only this — never an API key. sources: - openapi/cymetica-com-eventtrader-public-api-openapi.yml issuance: - POST /auth/login (email/password) -> access_token + refresh_token - POST /auth/register - SIWE wallet sign-in (EventTrader.from_wallet in the Python SDK) - name: OAuth2 type: oauth2 flows: - flow: authorizationCode authorizationUrl: https://cymetica.com/oauth/authorize tokenUrl: https://cymetica.com/oauth/token scopes: 3 sources: - openapi/cymetica-com-eventtrader-public-api-openapi.yml discovery: authorization_server_metadata: well-known/cymetica-com-oauth-authorization-server.json protected_resource_metadata: well-known/cymetica-com-oauth-protected-resource.json registration_endpoint: https://cymetica.com/oauth/register revocation_endpoint: https://cymetica.com/oauth/revoke userinfo_endpoint: https://cymetica.com/oauth/userinfo pkce: S256 grant_types: - authorization_code - refresh_token token_endpoint_auth_methods: - none - client_secret_post - client_secret_basic note: OAuth bearer tokens work on the REST API (/api/v1/*); the /mcp/v1 JSON-RPC endpoint uses X-API-Key (mcp.json authentication.oauth.note). - name: HMAC (api_secret) type: custom status: mentioned-not-specified description: POST /auth/api-key returns an api_secret "for HMAC-signed integrations" (docs); the signing scheme is not documented in the spec or the docs. sources: - https://cymetica.com/api-docs - https://cymetica.com/getting-started docs: https://cymetica.com/api-docs#authentication sources_searched: - https://cymetica.com/api-docs (Authentication, API Key Management) - https://cymetica.com/getting-started - https://cymetica.com/sdk (Authentication) - https://cymetica.com/.well-known/oauth-authorization-server - https://cymetica.com/.well-known/oauth-protected-resource - https://cymetica.com/.well-known/mcp.json - live 401 probe of GET /api/v1/portfolio/positions mcp: endpoint: https://cymetica.com/mcp/v1 anonymous_access: 57 public tools with no credentials header: X-API-Key trust_tiers: - unknown - recognized - trusted - allied