aw_ API key, and what a delegated payment authority artifact allows an agent to request.
API key and tool-level auth
Every live tool, includingread_page, discover, list_actions, and execute, requires an AgentWeb aw_ API key. Only the signup tools and agentweb_auth_status work unauthenticated. The MCP tool manifest declares each tool’s auth requirement and is the machine-readable source of truth.
The public readiness scan (POST /api/readiness/scan) and the discovery metadata files require no credentials, and do not execute forms or payments.
Payment authority scopes
Delegated payment authority artifacts carry ascope array. The valid values are defined by the payment authority schema:
scan.public_site: run a public readiness scan of a site.price.setup: read setup and usage pricing.create.setup_session: request an Agent Map setup session.generate.action_map_draft: generate a draft action map.verify.install: verify deployed agent-facing surfaces.execute.approved_action: execute approved mapped actions.
Billing boundary
API keys held by an agent connection cannot start AgentWeb billing. Checkout runs throughagentweb_create_checkout_session, which hands the signed-in customer a Dodo hosted checkout link. Credentials, private payloads, raw prompts, card data, and unrestricted API keys are never part of any scope.