Skip to main content
Limitguard supports two authentication modes: API key (prepaid balance) and x402 USDC micropayments (pay-per-use). Sandbox mode is available for testing without either.

API Key Authentication

Pass your API key in the X-API-Key header:
A paid-tier API key skips the per-call x402 payment: each call is debited at list price from the key’s prepaid balance instead. A free key still pays per call. The tier only selects the key’s rate limits (see Rate Limits).

Key Format

Creating Keys

POST /v1/keys/create can only provision free or sandbox tiers directly. To move up the ladder, create a free key first, then pay via POST /v1/keys/upgrade/{tier} (x402 required even if you already hold a key: see Pricing): A top-up buys balance, not a number of calls: each call is debited at its list price. Check the balance with GET /v1/keys/usage.
The plaintext key is returned once only: store it securely. It is never stored server-side.

x402 USDC Micropayments

For AI agents and pay-per-use access without a subscription. Send the base64-encoded JSON payment object in the PAYMENT-SIGNATURE header (x402 V2); the V1 X-PAYMENT header is still accepted.
See the full x402 Protocol guide for step-by-step implementation with code examples.

x402 V2 Flow

1

Request without payment

Make your API request normally. You’ll receive HTTP 402 with payment requirements.
2

Build payment signature

Construct an EIP-3009 TransferWithAuthorization signature using the payment details from the 402 response: network, asset, amount and payTo of the accepts entry you pay.
3

Retry with payment

Retry the same request with the PAYMENT-SIGNATURE header (or the V1 X-PAYMENT header) containing the base64-encoded payment object.

HTTP 402 Response

When you make a request without payment, the API returns the payment requirements (trimmed: the live body lists Base, Solana and a settled-transfer option, and recovery hints under extensions):
amount is in USDC 6-decimal units: 1050000 is the fresh price of POST /v1/entity/check today. Always pay the amount the 402 quotes; Pricing lists every endpoint. The full body is on the x402 Protocol page.

Supported Networks

The production API (api.limitguard.ai) quotes Base Mainnet and Solana Mainnet only: its /.well-known/x402.json says testnet_supported: false. The two testnets work only against a test environment that lists them in its accepts array.

V1 Backward Compatibility

PAYMENT-SIGNATURE is the x402 V2 header and is recommended for new integrations; it takes priority when both are sent. The older X-PAYMENT header (V1) is still accepted.

Response Headers on Success

Free Endpoints

These endpoints never require payment or authentication: