# auth.md — QR Studio agent registration

Procedural guide for agents using resources advertised from https://qr.strt.it.

## Discover

1. https://qr.strt.it/.well-known/ai-catalog.json (ARD / Agentmap)
2. https://qr.strt.it/.well-known/api-catalog (RFC 9727 linkset)
3. Optional: MCP `/.well-known/mcp/server-card.json`, A2A `/.well-known/agent-card.json`, skills `/.well-known/agent-skills/index.json`

## Agent registration

**Registration is not required.** QR Studio and the linked `a.strt.it` QR / business-card HTTP APIs are **public**.

### Supported method: anonymous (public)

| Field | Value |
|-------|-------|
| Identity type | `anonymous` |
| Register / provisioning URI | none — discovery is sufficient |
| Claim URI | none |
| Credentials issued | none |
| How to call APIs | HTTPS without an `Authorization` header |

### Registration steps (anonymous)

1. Confirm audience: generate QR codes or business-card images via public HTTP APIs  
2. Skip identity assertion and claim ceremonies — there is no `/agent/identity` endpoint  
3. Call the APIs directly (see Use)  
4. Revocation: not applicable (no tokens)

Do **not** invent bearer tokens or `POST` speculative auth or signup URLs for this product.

## Use

```http
GET https://a.strt.it/qr/code/image?data=https://example.com
POST https://a.strt.it/qr/code
GET https://a.strt.it/qr/bcard/image?...
```

Local MCP (stdio): `npx qr-mcp-server` — same public upstream APIs  
Card: https://qr.strt.it/.well-known/mcp/server-card.json  
Human/AI docs: https://a.strt.it/docs/AI-GUIDE.md

## OAuth / OIDC

This origin intentionally does **not** publish OAuth Authorization Server or Protected Resource Metadata: there is no authorization server and no protected resource. Empty stub OAuth documents would mislead agents. If API keys or OAuth are added later, this file and `/.well-known/oauth-protected-resource` will be updated together.
