generated: '2026-09-19' method: searched source: https://xguardgate.com/.well-known/ai-plugin.json derived_from: openapi/xguardgate-com-openapi.json probed: true docs: - https://xguardgate.com/developers - https://github.com/moelayyan90/XGuard/blob/main/docs/secretless-outcomes.md - https://api.xguardgate.com/.well-known/oauth-protected-resource - https://api.xguardgate.com/.well-known/xguard-egress.json summary: >- XGuard has no user accounts, no API-key signup and no OAuth. The OpenAPI declares NO securitySchemes (a contract-quality gap - the credentials exist only as header parameters and prose; overlays/ proposes four schemes), and the RFC 9728 documents on both the API and MCP resources say so plainly: bearer_methods_supported [], oauth_supported false, "Public discovery and pay-per-request tools do not require an XGuard account or OAuth bearer token." Authorization is layered by role instead. Anyone may discover, preview and quote. A PAID outcome is authorised by an x402 v2 payment - the retry of a 402 carries Payment-Signature and the preserved signed quote - so the wallet, not an account, is the principal. An OPERATOR who buys Usage Credits gets an X-XGuard-Key (stored server-side only as an irreversible hash) for credential custody, capability issuance and Action Rail permits; an AGENT acting for that operator receives a short-lived scoped capability (xgc_...) and never the upstream secret. Recovery of a paid result uses the original quote as a bearer token, and a signed execution credit (X-XGuard-Credit) redeems a failed paid execution. Merchant hosts authorise the Edge proxy by publishing a DNS TXT record rather than by any key. schemes: - id: anonymous type: none applies_to: [xguardExecute with intent:demo or html, 'GET /v1/capabilities', 'GET /v1/pricing', 'POST /v1/pricing/quote', 'POST /v1/preflight', 'POST /v1/test', 'GET /supported', 'GET /healthz', every /.well-known document, MCP initialize and tools/list, A2A card] evidence: 'Live 2026-09-19: POST /v1/execute {"intent":"demo"} -> 200 with no credential; POST /v1/pricing/quote -> 200; POST /mcp tools/list -> 200. Homepage: "No account. No API key. Pay only when you request live source execution."' - id: x402-payment type: payment (x402 v2, HTTP 402 challenge/response) headers: challenge: [Payment-Required, X-XGuard-Quote, x-xguard-payment-identifier] request: [Payment-Signature, X-XGuard-Quote] response: [Payment-Response, x-xguard-receipt, x-xguard-proof] principal: the paying wallet (Base USDC, EIP-3009 authorization); no account is created applies_to: - xguardExecute for web-extraction / product-offers / feed-digest - 'POST /v1/tools/web.fetch' - 'POST /v1/tools/web.fetch/testnet' - A2A skills (SendMessage) - 'MCP xguard_execute (challenge in the tool result; retry with params._meta["x402/payment"])' networks: {production: 'eip155:8453 (Base)', test: 'eip155:84532 (Base Sepolia), testnet:true'} evidence: 'openapi xguardExecute: header params X-XGuard-Quote, Payment-Signature, X-XGuard-Credit; 402 response headers Payment-Required + X-XGuard-Quote; description "An unsigned request only returns a price; it does not fetch sources or settle payment." Live 402 observed 2026-09-19 with accepts[{scheme exact, network eip155:8453, asset 0x8335...2913, payTo 0x4f32...ba07}].' docs: https://xguardgate.com/developers - id: xguard-key type: apiKey in: header name: X-XGuard-Key role: operator applies_to: ['POST /v1/egress/credentials', 'GET /v1/egress/credentials', 'POST /v1/egress/capabilities', 'DELETE /v1/egress/capabilities/{id} (declared required in the spec)', 'POST /v1/actions/permits', 'GET /v1/balance', 'GET /v1/ledger'] how_obtained: 'Issued with Operator Usage Credits (JOD 3.550 / 5,000 credits, Lemon Squeezy checkout at https://xguardgate.com/pricing/operator). The issuance flow itself is not documented publicly; the site warns "Do not place an operator key in an AI prompt."' storage: 'Provider stores only an irreversible hash of the key (privacy page).' errors: {401: [xguard_key_required, missing_xguard_license]} evidence: 'Live 2026-09-19: GET /v1/egress/credentials -> 401 {"error":{"code":"xguard_key_required",...}}; GET /v1/balance -> 401 missing_xguard_license; no WWW-Authenticate header. ai-plugin.json auth.authorization_type: "Operator management uses X-XGuard-Key".' docs: https://github.com/moelayyan90/XGuard/blob/main/docs/secretless-outcomes.md - id: scoped-capability type: capability token (bearer-like, passed in the JSON body field `capability`) prefix: xgc_ role: agent (delegated) applies_to: ['POST /v1/egress/fetch'] issued_by: 'POST /v1/egress/capabilities (operator, X-XGuard-Key) with credential_id, target_origin, path_prefix, allowed_methods, ttl_seconds 30-3600, max_calls, max_total_credits, max_credits_per_call' revoked_by: 'DELETE /v1/egress/capabilities/{id}' sdk: 'createXGuardAgentClient(process.env.XGUARD_CAPABILITY) in sdk/index.js' errors: {401: capability_required, 403: 'capability or credential scope denied', 402: 'budget exceeded before billing'} evidence: 'ai-plugin.json auth.authorization_type: "agent egress uses a scoped xgc_ capability"; /.well-known/xguard-egress.json security_model: "operator holds reusable secret; agent receives scoped short-lived XGuard capability".' - id: recovery-quote type: bearer (signed ES256 JWS quote, header X-XGuard-Quote) applies_to: ['GET /v1/results/{payment_identifier} (declared required in the spec)', MCP xguard_get_result] evidence: 'llms.txt Recovery: "This quote grants access to the stored public-source result; do not publish it." README: "treat that quote as a private bearer token." 403 "Unsafe target or recovery credential" on mismatch.' - id: execution-credit type: signed credential (header X-XGuard-Credit) applies_to: [xguardExecute retry after 502 'No usable source; execution credit retained'] evidence: 'openapi xguardExecute header param X-XGuard-Credit; pricing page: "the response provides an execution credit for the same outcome."' - id: action-permit type: signed single-use permit (ES256) bound to a mandate applies_to: ['POST /v1/actions/execute'] issued_by: 'POST /v1/actions/permits (X-XGuard-Key; 428 if no mandate)' public_key: https://api.xguardgate.com/.well-known/xguard-actions-key.json evidence: /.well-known/xguard-actions.json controls list. - id: merchant-dns-authorization type: domain-control proof (DNS TXT), not a credential applies_to: ['POST /edge/{merchant-host}/{path}'] record: '_xguard. TXT "xguard-edge=enabled"' errors: {403: 'Merchant hostname has not authorized XGuard Edge'} evidence: /docs edge.merchant_authorization; /healthz universal_edge. oauth2: false openid_connect: false protected_resource_metadata: api: well-known/xguardgate-com-oauth-protected-resource.json mcp: well-known/xguardgate-com-oauth-protected-resource-mcp.json authorization_servers: [] note: 'Served and truthful: they document that there is no OAuth. /.well-known/oauth-authorization-server returns a deliberate 404 ("XGuard does not advertise a fictitious OAuth issuer").' spec_gaps: - No components.securitySchemes and no security requirements in the OpenAPI, so a generated client cannot know which operations need X-XGuard-Key or a capability without reading the prose; proposed schemes are in overlays/xguardgate-com-openapi-overlay.yaml. - 401 responses carry no WWW-Authenticate header. key_hygiene: - 'Never enter a wallet private key into the site or an AI conversation (developers page); XGUARD_PAYER_PRIVATE_KEY stays in the local process environment.' - 'Do not place an operator key in an AI prompt (pricing/operator page).' - 'Agents receive capabilities, never upstream secrets; the response filter blocks literal, encoded and base64 credential reflections (docs/secretless-outcomes.md).'