# feerasta.ai auth.md

Agent authentication and registration guide for feerasta.ai.

## Who this is for

AI agents acting on behalf of business owners: browsing Feerasta's services,
comparing pricing, or filing a pilot request for their principal.

## Authentication model: anonymous

The entire public agent surface of feerasta.ai requires **no registration, no
account, and no credentials**:

- `GET /v1/catalog` (alias `GET /agents.json`): service and pricing catalog (JSON)
- `POST /v1/ask`: a question answered from approved FAQ text `{q}`
- `POST /v1/contact` (alias `POST /api/contact`): pilot request / inquiry
  `{name, business, email, message, phone?}`; add `"dry_run": true` (JSON or form body, on either path) to preview without sending. Real sends are limited to 3 per 60 seconds per client; dry runs are not limited
- MCP website server `https://feerasta.ai/mcp` (streamable-http, JSON-RPC):
  tools `list_services`, `get_service`, `ask_faq`, `request_pilot`
- MCP app server `https://app.feerasta.ai/api/public/mcp` (streamable-http, JSON-RPC):
  tools `list_services`, `get_service`, `start_trial`
- Any page with `Accept: text/markdown` returns a markdown representation

There is no OAuth authorization server, no token endpoint, and no API keys are
issued. Do not send bearer tokens; they are ignored.

## Agent registration

```json
{
  "agent_auth": {
    "skill": "https://feerasta.ai/agent-skills/request-pilot/SKILL.md",
    "register_uri": "https://feerasta.ai/v1/contact",
    "identity_types_supported": ["anonymous"],
    "anonymous": {
      "credential_types_supported": ["none"],
      "claim_uri": "https://feerasta.ai/agents.json"
    }
  }
}
```

Registration method `anonymous`: no credential is issued and none is needed;
agents claim access by calling the public endpoints directly. `register_uri`
is the human-provisioned path: it files a pilot request and a person at
Feerasta completes registration out of band.

## Registration

Supported registration methods for agents, in order of preference:

1. **Anonymous** (no registration): all endpoints in the previous section work
   without any signup. Credential types supported: none. This is the intended
   path for agents; claim it by simply calling the endpoints.
2. **Human-provisioned** (for Feerasta OS customer workspaces): registration
   endpoint `POST https://feerasta.ai/v1/contact`; a human at Feerasta
   provisions the account and issues credentials to the business owner by
   email. Agents cannot complete this flow programmatically past the initial
   request.

There is no self-serve agent registration endpoint and no dynamic client
registration.

## Provisioning (becoming a customer)

Client accounts on the Feerasta OS (app.feerasta.ai) are provisioned by the
Feerasta team after a pilot request, not self-registered. The registration
endpoint for that flow is human contact:

- `POST /v1/contact` with your principal's real name, email, and business, or
- https://feerasta.ai/contact

Credentials for the OS are then issued directly to the business owner. Agents
should never attempt to create OS accounts programmatically.

## Rate limits and identification

`POST /v1/ask` (and the MCP tool `ask_faq`) allow 5 requests per 60 seconds per
client; real contact sends (`POST /v1/contact`, `POST /api/contact`, the MCP tool
`request_pilot`) allow 3 per 60 seconds per client. Beyond that you get HTTP 429
with `Retry-After`. Dry runs, the catalog and health have no per-client limit. Full details: https://feerasta.ai/developers.
Standard polite-crawler behaviour applies. If your agent signs requests
(Web Bot Auth), we publish our own verification key at
`/.well-known/http-message-signatures-directory`.

## See also

- `/.well-known/api-catalog`: machine-readable API catalog (RFC 9727)
- `/.well-known/mcp/server-card.json`: MCP server card
- `/developers`: developer portal (API, MCP, errors, rate limits)
- `/openapi.json`: OpenAPI 3.1 description
- `/llms.txt`: answer-engine map of the whole site
