generated: '2026-09-19' method: searched source: openapi/getaiscan-app-openapi.json docs: - https://getaiscan.app/llms.txt - https://api.getaiscan.app/api/agent/index - https://getaiscan.app/.well-known/agent-card.json summary: types: - apiKey api_key_in: - header oauth2_flows: [] bearer: false credential_classes: 1 headline: >- No API key, no account, no signup, no OAuth. The single securityScheme in the contract is named "x402" and typed apiKey-in-header only because OpenAPI has no vocabulary for a payment credential: the header PAYMENT-SIGNATURE carries an x402 V2 payment — either a signed EIP-3009 "exact" authorization for USDC on Base settled through the Coinbase CDP facilitator, or the transaction hash of a direct USDC transfer to the provider's wallet. An unpaid call to any paid route returns HTTP 402 with a base64 PAYMENT-REQUIRED header and a JSON body naming the price, asset, network, recipient and both flows. GET /api/agent/index is the only unauthenticated route (security: []). schemes: - name: x402 type: apiKey in: header parameter: PAYMENT-SIGNATURE description: 'x402 V2 payment: signed payload or Base USDC tx hash' semantics: payment credential, not an identity credential — the paying wallet is the only identity the API sees protocol: name: x402 version: 2 network: eip155:8453 (Base mainnet) asset: USDC — 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 pay_to: '0x0a28ace35b9687a9334cd503b3c7d4b23734a1c7' flows: - id: exact description: EIP-3009 transferWithAuthorization signed by the payer, settled via the Coinbase CDP facilitator; the signed payload goes in PAYMENT-SIGNATURE. - id: direct-transfer description: Send the exact USDC amount on Base to pay_to, then retry the same request with PAYMENT-SIGNATURE set to the transaction hash. max_timeout_seconds: 300 challenge_observed: request: 'POST https://api.getaiscan.app/api/agent/check_health {"url":"https://example.com"} with no payment header, 2026-09-19' status: 402 headers: payment-required: base64 JSON — {x402Version 2, error "PAYMENT-SIGNATURE header is required", resource {url, description, mimeType}, accepts [{scheme exact, network eip155:8453, amount 60000, asset, payTo, maxTimeoutSeconds 300, extra {name USD Coin, version 2}}], extensions {}} x-payment-required: 'true' x-payment-version: '2' x-payment-amount: '0.06' x-payment-currency: USDC x-payment-network: eip155:8453 x-payment-recipient: '0x0a28ace35b9687a9334cd503b3c7d4b23734a1c7' x-payment-asset: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913' body_fields: [x402Version, error, resource, accepts, extensions, price, currency, recipient, instructions, capability, index] instructions_verbatim: >- Pay 0.06 USDC: x402 V2 'exact' scheme (PAYMENT-SIGNATURE header, settled via Coinbase CDP facilitator), or direct-transfer: send 0.06 USDC on Base (eip155:8453) to 0x0a28ace35b9687a9334cd503b3c7d4b23734a1c7 and retry with PAYMENT-SIGNATURE: note: The body's accepts[0].network says "base" while the header and the PAYMENT-REQUIRED payload say "eip155:8453"; the amount is in USDC base units (60000 = 0.06 USDC, 6 decimals). header_aliases: accepted_by_cors: [PAYMENT-SIGNATURE, Payment-Signature, X-Payment, X-PAYMENT] note: The legacy agent.json descriptor and the mcp.json descriptor name X-Payment; the OpenAPI, the agent card and the live challenge name PAYMENT-SIGNATURE. Use PAYMENT-SIGNATURE. applied_to: every POST /api/agent/{capability} operation (19 of 20 operations); the operations declare no per-operation security[] and the document declares no top-level security, so the requirement is expressed by the 402 response each operation declares rather than by a security requirement object exempt: [index] sources: - openapi/getaiscan-app-openapi.json gaps: - The OpenAPI declares the x402 scheme in components.securitySchemes but applies it nowhere (no top-level or per-operation security[] except index's empty list); a client generator will treat every operation as anonymous. - No OAuth/OIDC, no RFC 9728 protected-resource metadata, no RFC 8414 metadata on either host; there is nothing to discover beyond the 402 itself. - No testnet or sandbox payment path is documented; every call is a real mainnet USDC payment.