auth.md

Agent registration and authentication for HoneyCoin APIs.

Last updated: 2026-07-20

HoneyCoin does not currently expose a public OAuth/OIDC authorization server for agent self-registration. Agents authenticate with API keys issued from the B2B dashboard, then exchange them for short-lived Bearer tokens.

This file is the canonical discovery document for how AI agents and automated systems obtain and use credentials.

Audience

Registration (get credentials)

There is no automated POST /agent/auth self-registration endpoint yet. Provision access as follows:

  1. Create a business account: https://b2b.honeycoin.app/register
  2. Complete onboarding / KYB as required in the dashboard
  3. Create API keys: Dashboard → Developers → API Keys
  4. Copy:
    • API Key (format: HC_…)
    • Public Key

For enterprise / agent-network access, contact api@honeycoin.app or sales@honeycoin.app.

Supported authentication method

Method Status
API Key + Public Key → Bearer JWT Supported (production)
OAuth 2.0 / OIDC agent registration Not available
Anonymous agent claim flows Not available

Step 1 — Generate a Bearer token

POST https://api-v2.honeycoin.app/api/b2b/auth/generate-bearer-token
Content-Type: application/json
api-key: YOUR_API_KEY

{"publicKey": "YOUR_PUBLIC_KEY"}

Example response:

{
  "success": true,
  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.....",
  "expiresAt": 1752085041
}

Step 2 — Call APIs with the Bearer token

Authorization: Bearer YOUR_BEARER_TOKEN
Content-Type: application/json

Token lifetime: ~2 hours. Agents must refresh tokens before expiry.

Sandbox token generation uses the same path under:

https://api-v2.honeycoin.app/api/sandbox/b2b/auth/generate-bearer-token

API bases

Environment Base URL
Production (B2B / Fiat) https://api-v2.honeycoin.app/api/b2b
Sandbox (B2B / Fiat) https://api-v2.honeycoin.app/api/sandbox/b2b
Production (Crypto) https://crypto.honeycoin.app/api
Sandbox (Crypto) https://crypto.honeycoin.app/api/sandbox

Machine-readable discovery

Note: HoneyCoin publishes OAuth Authorization Server metadata (RFC 8414) at /.well-known/oauth-authorization-server and Protected Resource metadata (RFC 9728) at /.well-known/oauth-protected-resource for discovery. HoneyCoin does not run a standard interactive OAuth 2.0 authorization-code flow: the advertised token_endpoint is the real Bearer-token endpoint, and credentials are provisioned from the dashboard (API Key + Public Key). Tokens are signed with HS256 (symmetric), so the JWKS is empty by design. Follow the API Key + Public Key flow documented above.

Credential use rules

Contact