generated: '2026-09-19' method: searched source: >- Derived baseline from openapi/hergertsynthora-com-mesh-aggregate-openapi.yml (securitySchemes.x402Payment) by 0-working/derive-authentication.py, then upgraded from the provider's own auth statements: the agent card securitySchemes (x402 http scheme + X-WALLET apiKey), https://hergertsynthora.com/api/ (X-WALLET on core endpoints, 403 without it), https://api.hergertsynthora.com/llms.txt (free tier), the notary card and the live 402 responses observed 2026-09-19 (WWW-Authenticate x402 challenge, payment-required header, x-free-tier). docs: https://hergertsynthora.com/api/ summary: types: - apiKey - http api_key_in: - header model: >- Wallet-native, accountless. There is no sign-up, no API key issuance and no OAuth. A paid call authenticates itself by carrying a payment (X-PAYMENT); an unpaid trial call identifies itself by its wallet address (X-WALLET). The 59 per-service OpenAPIs and the notary spec declare NO securitySchemes at all - the requirement lives in info.x-payment / x-payment-info and the 402 response. schemes: - name: x402Payment type: apiKey in: header parameter: X-PAYMENT description: >- EIP-3009 transferWithAuthorization payload, USDC on Base (eip155:8453). Obtained by first calling the endpoint and reading the 402 challenge (accepts[] in the body; the same JSON base64url in the payment-required header; on the api gateway also a WWW-Authenticate: x402 network=..., asset=..., pay_to=..., max_amount=..., resource=... challenge). applies_to: every paid operation (global security in the aggregate; implied by x-payment-info in every per-service spec) sources: - openapi/hergertsynthora-com-mesh-aggregate-openapi.yml - live 402 on https://api.hergertsynthora.com/v1/wallet-enrich and https://notary.hergertsynthora.com/service - name: x402 type: http scheme: x402 description: >- How the agent cards declare the same requirement: "Pago por llamada x402: USDC en Base (eip155:8453). La primera llamada devuelve HTTP 402 con los terminos de pago; el pago se verifica on-chain y la respuesta incluye recibo firmado." Not an IANA-registered HTTP auth scheme; recorded because the live gateway does emit a WWW-Authenticate challenge with that token. sources: - a2a/hergertsynthora-com-agent-card.json (securitySchemes.x402) - a2a/hergertsynthora-com-notary-agent-card.json (securitySchemes.x402) - name: wallet type: apiKey in: header parameter: X-WALLET description: >- The caller's Base address (0x...). Two uses the provider documents: (1) free trial - send it instead of a payment and the product answers up to x-free-tier calls (1 or 3, per product) without charge; (2) the "nucleo" state and meshgraph endpoints treat it as an API key and answer 403 without it (docs section 02; the docs elide the host for those endpoints). sources: - a2a/hergertsynthora-com-agent-card.json (securitySchemes.wallet) - https://hergertsynthora.com/api/ - https://api.hergertsynthora.com/llms.txt - 402 body freeTier {callsPerWallet, header X-WALLET}; response header x-free-tier credentials: sign_up: none - no accounts; the wallet is the identity key_prefixes: none rotation: n/a sandbox_keys: none (see sandbox/hergertsynthora-com-sandbox.yml) transport: https_only: true tls: TLSv1.3 on apex, api and notary hosts (security/hergertsynthora-com-domain-security.yml) mcp: https://mcp.hergertsynthora.com/mcp - initialize and tools/list are anonymous; tools/call is x402-paid; no OAuth metadata served a2a: https://api.hergertsynthora.com/a2a - JSON-RPC, same x402 / X-WALLET model per the card's security[] gaps: - The per-service and notary OpenAPIs declare no securitySchemes, so a generic OpenAPI client sees them as unauthenticated. - The X-WALLET "nucleo" endpoints are documented without a host.