# Auth.md — Kirppiskettu Agent Authentication & Registration

## Agent Registration
Kirppiskettu supports automated agent registration and discovery following the open Auth.md standard.

### Registration Details
- **Audience**: Autonomous AI Agents, Multi-Agent Systems, WebMCP clients, and Automated Crawlers.
- **Registration Endpoint**: `https://kirppiskettu.fi/.well-known/oauth-authorization-server`
- **Claim URI**: `https://kirppiskettu.fi/auth.md`
- **Revocation URI**: `https://kirppiskettu.fi/auth.md`
- **Supported Methods**: `anonymous`, `identity_assertion`, `client_credentials`
- **Identity Types Supported**: `anonymous`, `identity_assertion`
- **Credential Types Supported**: `none`, `ephemeral`, `bearer`

### Flow: Anonymous Access (Zero-Friction)
All core public flea market registries, circular value calculators, table rental breakeven analytics, and guides require no credentials (`identity_types_supported: ["anonymous"]`). Autonomous agents may query these endpoints directly.

## Discovery Endpoints
- **API Catalog (RFC 9727)**: `https://kirppiskettu.fi/.well-known/api-catalog`
- **Protected Resource Metadata (RFC 9728)**: `https://kirppiskettu.fi/.well-known/oauth-protected-resource`
- **Authorization Server Metadata (RFC 8414)**: `https://kirppiskettu.fi/.well-known/oauth-authorization-server`
- **ARD Capability Manifest**: `https://kirppiskettu.fi/.well-known/ai-catalog.json`
- **Context / LLM Discovery**: `https://kirppiskettu.fi/llms.txt`

## Rate Limits & Privacy
- **Rate Limit**: Standard 60 requests / minute per client IP.
- **Zero-PII & GDPR**: All processing occurs client-side without user profiling or tracking cookies.
