# ModAssemble agent authentication

The public website explains the product. It does not issue staff logins or payment tokens.

## Discover

Read the `agent_auth` block at https://modassemble.com/.well-known/oauth-authorization-server. The `identity_endpoint` is https://modassemble.com/agent/identity. Protected-resource metadata is https://modassemble.com/.well-known/oauth-protected-resource.

## Pick a method

Anonymous reading is the method this public site supports. Use https://modassemble.com/api/v1/plans and the Markdown pages. `identity_assertion` is not accepted. `service_auth` is not accepted. The ID-JAG type `id-jag` (`urn:ietf:params:oauth:token-type:id-jag`) is not accepted.

## Register

There is no client registration on the public site. An anonymous agent may read the public pages and the plan list.

## Claim

There is no claim endpoint. Do not send a claim.

## Exchange

There is no token exchange. A request to `/api` without a session receives `WWW-Authenticate: Bearer resource_metadata="https://modassemble.com/.well-known/oauth-protected-resource"`.

## Use the access_token

Do not send an access token for public facts. Workspace records require a person to sign in.

## Errors

HTTP 401 means the path is an API entry and the metadata above is the next step. HTTP 404 means the URL is not a ModAssemble page.

## Revocation

Nothing to revoke. Anonymous access does not create a session.
