# Authentication for Agent Plugins Directory

Agent Plugins Directory is a public read-only catalog. There is no login wall for the census, markdown pages, or the documentation MCP. This file is the WorkOS-shaped walkthrough an agent should follow.

## Discover

Start at the protected-resource metadata (RFC 9728) and the authorization-server metadata (RFC 8414):

- [/.well-known/oauth-protected-resource](https://agentpluginsdirectory.com/.well-known/oauth-protected-resource) — `resource`, `authorization_servers`, `bearer_methods_supported`, `scopes_supported`
- [/.well-known/oauth-authorization-server](https://agentpluginsdirectory.com/.well-known/oauth-authorization-server) — issuer, authorization_endpoint, token_endpoint, plus the `agent_auth` block (`register_uri`, `identity_types_supported`)
- [WWW-Authenticate](https://agentpluginsdirectory.com/agent/auth) — a 401 on `/agent/auth`, `/api`, and `/api/v1` carries `WWW-Authenticate: Bearer resource_metadata=...` so a client that probes first does not have to guess the well-known path

The `agent_auth.skill` field on the AS metadata points back at this file.

## Pick a method

Use **anonymous**. `identity_types_supported` is `["anonymous"]`. There is no `identity_assertion` / id-jag / verified_email path on this host. Public GET surfaces do not need a Bearer token. Send no cookie and no API key.

## Register

POST [register_uri](https://agentpluginsdirectory.com/oauth/register) (`/oauth/register`). The endpoint exists so the discovery chain is traversable. The response is a public client record (`client_id: public`). Dynamic client registration does not issue secrets because there is nothing to protect.

## Claim

POST [claim_uri](https://agentpluginsdirectory.com/oauth/token) (`/oauth/token`). The token endpoint answers honestly: this issuer does not mint access tokens. Read the JSON error and continue unauthenticated. There is no authorization-code or client-credentials grant that succeeds.

## Use the credential

Do not send `Authorization: Bearer`. Call:

- GET [/census.json](https://agentpluginsdirectory.com/census.json)
- GET [/api/v1/plugins](https://agentpluginsdirectory.com/api/v1/plugins)
- POST [/mcp](https://agentpluginsdirectory.com/mcp)

If a probe hits `/api` or `/agent/auth` without a token, expect 401 plus the WWW-Authenticate hint, then fall back to the public documents above.

## Errors

Unknown `/api/*` paths return RFC 9457 `application/problem+json` with `title`, `status`, `detail`, `code`, `message`, and `resolution`. 406s from content negotiation use the same model. 429s include `Retry-After` and RFC RateLimit headers.

## Revocation

POST [revocation_uri](https://agentpluginsdirectory.com/oauth/revoke) (`/oauth/revoke`). There are no tokens to revoke. The endpoint returns a structured acknowledgement so an agent that implements the walkthrough does not hit a 404.

## Out of scope

No user account, no paid plan, no brand-search product, no ChatGPT-app listing on this host.
