# auth.md

pcb.express public API: anonymous access. Credentials exist but are optional today.

## Agent audience

AI agents and scripts fetching PCB quotes (`GET /api/quote`), running Gerber pre-checks (`POST /api/analyze`) and saving quotes with an e-mail (`POST /api/leads`).

## Access

- All documented endpoints accept unauthenticated requests. No account is needed.
- Send a descriptive User-Agent. Abusive traffic is rate limited at the edge.
- `POST /api/leads` stores the e-mail you submit, for the launch notification only. Privacy notice: https://pcb.express/en/privacy

## OAuth metadata

- Protected Resource Metadata (RFC 9728): https://pcb.express/.well-known/oauth-protected-resource
- Authorization Server Metadata (RFC 8414): https://pcb.express/.well-known/oauth-authorization-server (issuer `https://pcb.express`)
- Scopes: `quote:read`, `gerber:analyze`, `lead:write`. Bearer tokens go in the `Authorization` header.

## Registration (anonymous)

Claim a bearer token without any identity:

```
curl -X POST https://pcb.express/api/agent/claim
```

`POST /api/agent/token` with `grant_type=client_credentials` behaves the same; no client authentication is required (`token_endpoint_auth_methods_supported: ["none"]`).

## agent_auth

As served in both metadata documents above:

```json
{
  "agent_auth": {
    "skill": "https://pcb.express/auth.md",
    "register_uri": "https://pcb.express/api/agent/claim",
    "claim_uri": "https://pcb.express/api/agent/claim",
    "identity_types_supported": ["anonymous"],
    "anonymous": {
      "credential_types_supported": ["bearer_token"],
      "claim_uri": "https://pcb.express/api/agent/claim"
    }
  }
}
```

Tokens are issued for forward compatibility: they are accepted but not yet required or validated, and every endpoint keeps working without one. When authenticated ordering launches, this file and the metadata above will announce the change before anything is enforced.

Docs: https://pcb.express/en/agents | OpenAPI: https://pcb.express/openapi.json | Catalog: https://pcb.express/.well-known/api-catalog
