generated: '2026-09-19' method: searched source: https://humanmirror.fr/connect/, https://humanmirror.fr/docs/vibecode/, https://humanmirror.fr/llms.txt, https://humanmirror.fr/skill.md, https://humanmirror.fr/.well-known/mcp.json, /forge-mcp.json, /nexus.json, the three registry server.json files, and every securityScheme in the 16 contracts under openapi/ (listed verbatim below); live 402 challenge observed 2026-09-19 docs: null summary: types: - http bearer (per-product prefixed API keys) - apiKey in header (X-API-Key, HumanMirror Pro) - x402 payment signature (PAYMENT-SIGNATURE header, not an OpenAPI securityScheme) - none (discovery, quotes, verification, Magnet, MCP tools/list) oauth2: false oidc: false mtls: false note: 'No OAuth anywhere: /.well-known/oauth-authorization-server, oauth-protected-resource and openid-configuration all 404. Identity is a bearer key whose PREFIX names the product that issued it, and on pay-per-call routes the credential is the payment itself.' credential_classes: - name: Nexus key header: 'Authorization: Bearer hm_nexus_…' products: - Nexus - Outcome - One - Flow - AgentOps how_to_get: POST https://humanmirror.fr/api/nexus/trial/ (100 free credits, one trial per network origin per 90 days; 409 if already issued) or Stripe checkout POST /api/nexus/checkout/ then POST /api/nexus/claim/ spec_schemes: - NexusBearer - BearerAuth - name: Forge key header: 'Authorization: Bearer hm_forge_…' products: - Forge how_to_get: POST https://humanmirror.fr/api/forge/trial (25 calls) or the 4.99 EUR pack spec_schemes: - BearerAuth (forge) - name: Oracle key header: 'Authorization: Bearer hm_oracle_…' products: - Oracle how_to_get: 4.99 EUR pack (100 credits) via Stripe spec_schemes: - ApiKeyBearer - name: Omni-Sync key header: 'Authorization: Bearer hm_omni_…' products: - Omni-Sync - Shared Context Engine (credits first, x402 fallback) how_to_get: POST /api/omni-sync/checkout/ (1.99 / 9.99 / 49.99 EUR packs) spec_schemes: - OmniSyncApiKey - name: Enterprise Guard key header: 'Authorization: Bearer hm_guard_…' products: - Enterprise Guard preflight (/api/v1/enterprise-guard/preflight/) how_to_get: Enterprise Guard subscription (1 500 / 3 000 / 5 000 EUR per month) spec_schemes: [] note: documented on /enterprise-guard/ only; no OpenAPI - name: HumanMirror Pro key header: 'X-API-Key: (README example prefix hm_live_)' products: - Pro SaaS (/api/v1/saas/*) - Next-Gen preview routes (/v1/agent/intent-proof/, /v1/fleet/consensus-lock/, /v1/m2m/escrow-settle/, /v1/agent/state-and-trust/) subject to the Pro monthly quota how_to_get: HumanMirror Pro subscription, 49 EUR/month (https://humanmirror.fr/dashboard/) spec_schemes: - HumanMirrorProApiKey - name: Enterprise Fleet pass header: 'Authorization: Bearer ' products: - Unlimited Payload Normalizer + Consensus Oracle + Sanitize Shield for 30 days; Next-Gen preview included; referral routes how_to_get: POST https://humanmirror.fr/api/x402/enterprise-pass/ paying 297 USDC via x402 spec_schemes: - EnterpriseBearer - name: Genesis allocation token header: 'Authorization: Bearer ' products: - POST /api/v1/m2m/resource/ (20 context_compress calls / 48h) how_to_get: POST /api/v1/m2m/handshake/ then POST /api/v1/m2m/claim-resource/ (skill.md) spec_schemes: [] - name: x402 payment signature header: 'PAYMENT-SIGNATURE: ' products: - every /api/x402/* route, /api/v1/m2m/*, /api/v1/consensus/verify/, /api/v1/sanitize/shield/, /api/v1/zero/, /api/market/intent|award, /v1/agent/perception-vector/, Agent OS state-and-trust how_to_get: Call without it, read the PAYMENT-REQUIRED header on the 402 (x402Version 2, accepts[] amount/payTo/network eip155:8453/asset USDC), sign, retry observed: '2026-09-19: POST /api/x402/secret-scanning/ -> 402 ''PAYMENT-SIGNATURE header is required''' spec_schemes: [] note: Declared as a header parameter on 68 operations rather than as a securityScheme. - name: Anonymous header: null products: - MCP initialize/tools/list on all seven servers - GET discovery endpoints (/api/v1/sanitize/shield/, /api/v1/m2m/payload-normalizer/, /api/v1/consensus/verify/, /api/v1/sink/, /api/v1/zero/, /api/automata, /api/magnet/*, /api/market/live/) - POST /api/outcome/quote/, /api/outcome/verify/, /api/flow/quote/, /api/solve/, /api/nexus/search, /api/trace/verify how_to_get: nothing spec_schemes: [] schemes: - name: HumanMirrorProApiKey type: apiKey scheme: null in: header parameter: X-API-Key bearerFormat: null description: Active HumanMirror Pro API key. Grants Next-Gen Preview access subject to the Pro monthly API quota. source: openapi/humanmirror-fr-x402-openapi.yml - name: EnterpriseBearer type: http scheme: bearer in: null parameter: null bearerFormat: hmep1 description: Active HumanMirror Enterprise Fleet pass. Next-Gen Preview is included. source: openapi/humanmirror-fr-x402-openapi.yml - name: OmniSyncApiKey type: http scheme: bearer in: null parameter: null bearerFormat: hm_omni_* description: HumanMirror Omni-Sync API key. One credit per Shared Context operation when credits are available. source: openapi/humanmirror-fr-x402-openapi.yml - name: ApiKeyBearer type: http scheme: bearer in: null parameter: null bearerFormat: hm_oracle_… description: null source: openapi/humanmirror-fr-oracle-openapi.yml - name: BearerAuth type: http scheme: bearer in: null parameter: null bearerFormat: hm_forge_* description: null source: openapi/humanmirror-fr-forge-openapi.yml - name: BearerAuth type: http scheme: bearer in: null parameter: null bearerFormat: hm_nexus_* description: null source: openapi/humanmirror-fr-nexus-openapi.yml - name: NexusBearer type: http scheme: bearer in: null parameter: null bearerFormat: hm_nexus_* description: null source: openapi/humanmirror-fr-agentops-openapi.yml - name: BearerAuth type: http scheme: bearer in: null parameter: null bearerFormat: hm_nexus_* description: null source: openapi/humanmirror-fr-outcome-openapi.yml - name: BearerAuth type: http scheme: bearer in: null parameter: null bearerFormat: hm_nexus_* description: null source: openapi/humanmirror-fr-one-openapi.yml - name: BearerAuth type: http scheme: bearer in: null parameter: null bearerFormat: hm_nexus_* description: null source: openapi/humanmirror-fr-flow-openapi.yml - name: bearerAuth type: http scheme: bearer in: null parameter: null bearerFormat: null description: null source: openapi/humanmirror-fr-physical-oracle-openapi.yml key_prefix_map: hm_nexus_: Nexus / Outcome / One / Flow / AgentOps hm_forge_: Forge hm_oracle_: Oracle hm_omni_: Omni-Sync / Shared Context hm_guard_: Enterprise Guard hm_live_: Pro (X-API-Key, README example) hmep1: Enterprise Fleet pass bearerFormat privacy_note: The privacy policy states HumanMirror stores a cryptographic digest of the API key, a request id, route, tool, hashed IP, status, latency and credits — not raw payloads. notes: - 'The derive-authentication.py baseline (method: derived) merged nine differently named bearer schemes into one row because they share type/scheme; this searched profile keeps each scheme with its own bearerFormat and source.' - Keys are never sent as query parameters; every scheme is a header.