generated: '2026-09-19' method: searched source: openapi/llama-box-crvusd-yield-optimizer-openapi.yml docs: - https://llama.box/yo/docs - https://llama.box/yo/api/pricing probed: true summary: types: - apiKey api_key_in: - header oauth2_flows: [] bearer: false security_schemes_declared: 0 headline: >- The contract declares NO components.securitySchemes and no security[] requirement — derive-authentication.py found nothing to profile — yet six of its ten operations accept an optional X-API-Key header as an ordinary parameter, and the live service enforces it: an invalid key returns 401 {"detail":"Invalid API key"}. The real gate on the four paid operations is x402 payment (HTTP 402 with a PAYMENT-REQUIRED header, USDC on Base Sepolia); the key is the alternative that bypasses it, tied to a "pro or enterprise tier" the rebalance operation mentions and nothing publishes. Free operations need neither. No OAuth, no OIDC, no bearer tokens, no discovery documents on the host. schemes: - name: X-API-Key (undeclared) type: apiKey in: header parameter: X-API-Key declared_as: >- An optional header PARAMETER (anyOf string|null, required: false) on each operation — not a securityScheme. A generator reading securitySchemes sees an unauthenticated API. used_by: [list_pools_api_pools_get, best_yield_api_best_yield_get, risk_score_api_risk_score__pool_id__get, simulate_rebalance_api_rebalance_post, a2a_endpoint_a2a_post, a2a_stream_endpoint_a2a_stream_post] issuance: >- Not published. The simulate_rebalance description says "Requires pro or enterprise tier"; /yo/api/pricing lists per-request x402 prices and the contact api@chado.studio but no tier, signup or key-issuance page. observed: - {request: 'GET https://llama.box/yo/api/best-yield?top=1 with X-API-Key: invalid-probe', status: 401, body: '{"detail":"Invalid API key"}', fetched: '2026-09-19'} - {request: 'GET https://llama.box/yo/api/best-yield?top=1 with no key', status: 200, fetched: '2026-09-19', note: free operation} - {request: 'POST https://llama.box/yo/api/rebalance with no key', status: 402, body: '{}', fetched: '2026-09-19', note: paid operation — x402 challenge in the PAYMENT-REQUIRED header} sources: - openapi/llama-box-crvusd-yield-optimizer-openapi.yml - name: x402 payment type: payment standard: x402 v2 (HTTP 402 Payment Required) in: header parameter: X-PAYMENT (request) / PAYMENT-REQUIRED (challenge response) description: >- Per /yo/api/pricing: "1. Request any paid endpoint without payment -> get 402 with payment details. 2. Sign a USDC payment on Base using the returned parameters. 3. Resend request with X-PAYMENT header -> get 200 with data." The observed challenge is x402Version 2, scheme "exact", network eip155:84532 (Base Sepolia testnet), asset 0x036CbD53842c5426634e7929541eC2318f3dCF7e (extra.name USDC, extra.version 2), payTo 0x6a1175D0EA0e6817786Ce51F1C4F3294F907f410, maxTimeoutSeconds 300, amount 10000 base units ($0.01) for POST /a2a. applies_to: - {operation: risk_score_api_risk_score__pool_id__get, price: '$0.005'} - {operation: simulate_rebalance_api_rebalance_post, price: '$0.01'} - {operation: a2a_endpoint_a2a_post, price: '$0.01'} - {operation: a2a_stream_endpoint_a2a_stream_post, price: '$0.01'} free_operations: [health_health_get, list_pools_api_pools_get, best_yield_api_best_yield_get, pricing_api_pricing_get, agent_card__well_known_agent_json_get, access_log_api_access_log_get] note: >- Not a securityScheme in the OpenAPI and not declared in the agent card. The paid operations declare only 200 and 422 responses; the 402 is undocumented in the contract and discoverable only by calling. sources: - https://llama.box/yo/api/pricing - a2a/llama-box-a2a.yml (x-evidence: decoded PAYMENT-REQUIRED header) discovery_documents: openid_configuration: 404 oauth_authorization_server: 404 oauth_protected_resource: 404 note: See well-known/llama-box-well-known.yml.