Skip to main content
Limitguard supports two authentication modes: API key (subscription) and x402 USDC micropayments (pay-per-use). Sandbox mode is available for testing without either.

API Key Authentication

Pass your API key in the X-API-Key header:
A paid-tier API key skips the per-call x402 payment: each call is debited at list price from the key’s prepaid balance instead. A free key still pays per call. The tier only selects the key’s rate limits (see Rate Limits).

Key Format

Creating Keys

POST /v1/keys/create can only provision free or sandbox tiers directly. To move up the ladder, create a free key first, then pay via POST /v1/keys/upgrade/{tier} (x402 required even if you already hold a key — see Pricing): A top-up buys balance, not a number of calls: each call is debited at its list price. Check the balance with GET /v1/keys/usage.
The plaintext key is returned once only — store it securely. It is never stored server-side.

x402 USDC Micropayments

For AI agents and pay-per-use access without a subscription. Include the X-PAYMENT header with a base64-encoded JSON payment object.
See the full x402 Protocol guide for step-by-step implementation with code examples.

x402 V2 Flow

1

Request without payment

Make your API request normally. You’ll receive HTTP 402 with payment requirements.
2

Build payment signature

Construct an EIP-3009 TransferWithAuthorization signature using the payment details from the 402 response.
3

Retry with payment

Retry the same request with the X-PAYMENT header containing the base64-encoded payment object.

HTTP 402 Response

When you make a request without payment, the API returns the payment requirements:

Supported Networks

V1 Backward Compatibility

The legacy PAYMENT-SIGNATURE header is still accepted (V1 format). V2 (X-PAYMENT) is recommended for new integrations.

Response Headers on Success

Free Endpoints

These endpoints never require payment or authentication: