generated: '2026-09-19' method: searched source: - https://namewhisper.ai/auth.md - https://namewhisper.ai/.well-known/oauth-authorization-server - https://namewhisper.ai/.well-known/oauth-protected-resource - https://namewhisper.ai/.well-known/erc8128 - https://namewhisper.ai/docs - https://namewhisper.ai/terms docs: https://namewhisper.ai/auth.md description: >- Authentication profile for Name Whisper's agent surfaces. There is no OpenAPI, so this is read from the provider's own auth.md ("the authoritative source for how AI agents authenticate"), the RFC 8414 / RFC 9728 metadata documents it publishes, the ERC-8128 discovery document, and confirmed by live probes on 2026-09-19. The MCP and A2A endpoints are anonymous by default; ERC-8128 signed HTTP requests are the opt-in identity layer; no bearer tokens or API keys are ever issued. summary: types: [none, erc8128-signed-request, oauth2-metadata] schemes: - name: anonymous type: none surface: MCP https://namewhisper.ai/mcp and A2A https://namewhisper.ai/a2a description: >- All 44 tools are callable with no credential ("All 44 tools become available with no API key" - /guide). initialize, tools/list and an A2A message/send all succeeded anonymously. Unsigned callers get an anonymous result from get_caller_identity and no identity-aware features (reputation, usage tracking). probe: {url: 'https://namewhisper.ai/mcp', method: POST tools/list, status: 200, credentials: none} - name: erc8128 type: erc8128-signed-request surface: MCP https://namewhisper.ai/mcp (and the REST twins under /api/*) description: >- Per-request cryptographic authentication: each HTTP request is signed by the caller's Ethereum wallet (ERC-8128, https://erc8128.slice.so, EIP draft 8128). Accepted signing algorithms ES256K, EIP191 and EIP1271 (smart-contract wallets). Policy from the discovery document: maxValiditySec 300, replay protection via a nonce store, smart contract wallets supported. Signatures are verified per request and never exchanged for a bearer token. auth.md states write and transaction tools "require a signed request so the caller's wallet is verifiable", while the discovery document and docs call ERC-8128 optional; live, the transaction tools return unsigned calldata for whatever walletAddress is passed, and it is the caller's wallet that ultimately signs. discovery: https://namewhisper.ai/.well-known/erc8128 custody: none - transaction tools return unsigned transactions; the provider never holds keys sources: [https://namewhisper.ai/.well-known/erc8128, https://namewhisper.ai/auth.md] - name: oauth-metadata type: oauth2-metadata surface: https://namewhisper.ai (issuer) for resource https://namewhisper.ai/mcp description: >- RFC 8414 authorization-server metadata and RFC 9728 protected-resource metadata are published "for agent tooling that expects it", but the flows they describe are not standard OAuth: grant_types_supported is [erc8128_signed_request], response_types_supported is [none], token_endpoint_auth_methods_supported is [none, erc8128], and the note says "no bearer tokens are issued". The documents carry an agent_auth block whose register/claim/identity endpoints are all the MCP endpoint itself and whose registration tool is provision_agent_identity (an on-chain ENSIP-25 / ERC-8004 identity, not an OAuth client). /oauth/authorize and /oauth/token are named as endpoints but were not exercised. issuer: https://namewhisper.ai authorization_endpoint: https://namewhisper.ai/oauth/authorize token_endpoint: https://namewhisper.ai/oauth/token scopes: [mcp.read, mcp.transact] files: - well-known/namewhisper-ai-oauth-authorization-server.json - well-known/namewhisper-ai-oauth-protected-resource.json - name: siwe type: sign-in-with-ethereum surface: web app (namewhisper.ai) only description: >- The terms state "Authentication uses Sign-In with Ethereum (SIWE). Your account is tied to your Ethereum address" and the privacy policy that the session is a JWT in localStorage. This is the human web app's login, not an API credential, and is recorded for completeness. sources: [https://namewhisper.ai/terms, https://namewhisper.ai/privacy] oauth: metadata-only openid_connect: false api_keys: false notes: >- /.well-known/openid-configuration returns 404 - the issuer publishes RFC 8414 metadata but is not an OpenID Provider. No API-key scheme exists anywhere. The scopes mcp.read and mcp.transact are recorded in scopes/namewhisper-ai-scopes.yml.