generated: '2026-09-19' method: searched source: https://api.verse-me.com/.well-known/agent.json docs: - https://api.verse-me.com/.well-known/agent.json spec: null summary: types: - payment - none api_key_in: [] oauth2_flows: [] bearer: false credential_classes: 2 headline: >- No account, no API key, no signup. Verse's only credential is money: paid endpoints answer HTTP 402 with x402 payment requirements, the caller pays USDC on Base and retries with the payment receipt header; the calibration and reputation endpoints are declared public. There is no OpenAPI, so derive-authentication.py had nothing to read — the profile is the agent card's securitySchemes / securityRequirements plus the x402 block in its extensions. None of it could be exercised live: every application path answers a Cloudflare managed challenge to a non-browser client. schemes: - name: x402Payment type: payment standard: x402 (HTTP 402) in: header (payment receipt on the retried request) headers_named_by_edge: [PAYMENT-SIGNATURE, X-PAYMENT] response_headers_named_by_edge: [PAYMENT-REQUIRED, PAYMENT-RESPONSE] network: eip155:8453 (Base mainnet) asset: USDC asset_contract: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913' facilitator: https://openfacilitator.io pay_to: '0x1060D0B596685Ff429BD64f41611f5D1d15f1659' applies_to: - consultation (POST /expertise/consultation) - epistemic_audit (POST /expertise/epistemic-audit) - edgar_financial_intelligence (POST /expertise/edgar) - strategy_recommendation (routed through the consultation endpoint per the card) description: >- Verbatim from the card: "x402 HTTP payment protocol. Client receives 402 response with payment requirements, pays onchain (Base USDC), retries with payment receipt header. No API keys or accounts needed." gettingStarted step 2: "Verse replies with the price first, usually $3–$25 USDC on Base ... sign the payment authorization with your wallet and retry the request with the receipt." The card's CORS headers (Access-Control-Allow-Headers: Content-Type, PAYMENT-SIGNATURE, X-PAYMENT, X-Console-Token; Access-Control-Expose-Headers: PAYMENT-REQUIRED, PAYMENT-RESPONSE) name the request and response headers the payment flow uses. A planned second rail is named (x402 on Canton, asset USDCx) but not live. observed: >- Not observed. POST /expertise/consultation without payment returned the Cloudflare challenge (403), so the 402 body and PaymentRequirements shape are unverified. sources: - https://api.verse-me.com/.well-known/agent.json - name: public type: none applies_to: - calibration_track_record (GET /expertise/calibration) - calibration_history (GET /expertise/calibration/history) - signed_calibration (GET /expertise/calibration/signed, GET /expertise/calibration/history/signed) - reputation / proof bundle (GET /reputation) - price estimate (POST /expertise/consultation/price-estimate) description: 'Verbatim: "No authentication required. Public read-only access." The AGP policy for these capabilities is requiresAuth false, cost 0, dataScope aggregate_only.' observed: >- Not reachable by a non-browser client: GET /expertise/calibration returned the Cloudflare managed challenge (403, cf-mitigated: challenge) under three different User-Agents and Accept: application/json. The endpoint is public in policy and challenged at the edge in practice, which is the gap an agent will hit first. sources: - https://api.verse-me.com/.well-known/agent.json - name: X-Console-Token type: apiKey in: header parameter: X-Console-Token audience: internal (inferred from the name only) description: >- Not declared in the card. Appears only in the Access-Control-Allow-Headers of the card response alongside the payment headers. Recorded because it is observable; its purpose is undocumented and it should not be treated as a customer credential. sources: - HTTP response headers of https://api.verse-me.com/.well-known/agent.json discovery: oauth_authorization_server: 404 oauth_protected_resource: 404 openid_configuration: 404 identity_and_provenance: agent_identity: Ed25519 key published in the card (fingerprint 153b303b701f1a67) signs outputs; ERC-8004 agentId 29481 on Base, owner wallet = payTo wallet (verified on-chain). note: These authenticate Verse to its callers; they are not caller credentials.