generated: '2026-09-19' method: searched docs: https://theloopbreaker.com/llms.txt source: >- derive-authentication.py found no securitySchemes (components.securitySchemes is {} and no global or per-operation security[] in openapi/theloopbreaker-com-openapi.yml). The profile below is therefore from the provider's own statements — the OpenAPI info.description ("All endpoints are public and require no authentication for reads"), the agent card (authentication.schemes ["none"]; "Write endpoints return unsigned transactions for the caller to sign"), ai-plugin.json (auth.type none), SKILL.md ("ERC-8128 — signed HTTP requests from agent wallets — request authentication without API keys"), the @vaultfire/mcp-server README (PRIVATE_KEY env for write tools) — and from live 2026-09-19 probes. summary: types: [none, erc-8128-http-signature, x402-payment, wallet-signature] api_key_in: [] oauth2_flows: [] api_keys: false oauth2: false oidc: false mtls: false schemes: - name: publicRead type: none applies_to: every GET operation in openapi/theloopbreaker-com-openapi.yml and the two free x402 endpoints (/api/x402/trust/health, /api/x402/oracle/chainlink-status) evidence: 'GET /api/agent/status?address=0xfA15...813C -> 200 with no credential (2026-09-19)' - name: erc8128HttpSignature type: http-message-signature standard: ERC-8128 (profile of RFC 9421 HTTP Message Signatures, signed by the agent wallet key) headers: [Signature, Signature-Input] applies_to: routeTask (POST /agent/route) — observed; possibly other write operations, which the spec does not say evidence: 'POST /api/agent/route {} -> 401 {"error":"unsigned","reason":"Request is missing ERC-8128 Signature and/or Signature-Input headers"}' documented_in_spec: false - name: x402Payment type: payment standard: x402 v2, scheme exact, USDC on Base (eip155:8453) headers: [PAYMENT-SIGNATURE (request), PAYMENT-REQUIRED (402 challenge), PAYMENT-RESPONSE (settled response)] applies_to: 75 priced endpoints under /api/x402/* (well-known/theloopbreaker-com-x402.json) facilitator: https://api.cdp.coinbase.com/platform/v2/x402 evidence: '402 challenge observed on GET /api/x402/bonds/agent-bond-status and POST /api/x402/actions/accept-bid' - name: walletSignature type: self-custody applies_to: registerAgent, createBond, prepareTask, prepareVKPAction — the API returns an unsigned transaction / contract ABI; state changes happen only when the caller signs and broadcasts with their own wallet evidence: OpenAPI response descriptions ("Unsigned transaction to submit on-chain"); agent card authentication.note; Terms section 3 (self-custody) - name: mcpPrivateKey type: environment-secret applies_to: the two write tools of the stdio MCP server (vaultfire_register_agent, vaultfire_create_bond) variable: PRIVATE_KEY evidence: '@vaultfire/mcp-server README, "Write Tools (require PRIVATE_KEY env var)"' note: A wallet private key held by the local process, never sent to Vaultfire. credential_issuance: none — there is no sign-up, API key or OAuth client; identity is the caller's wallet address spec_gap: >- The contract declares no securitySchemes at all, so the ERC-8128 requirement on routeTask and the x402 requirement on the priced surface are invisible to a generated client. Captured in overlays/theloopbreaker-com-openapi-overlay.yaml.