# auth.md

AutoRFP.ai is the accuracy-first, AI-native, source-grounded platform for RFPs, security questionnaires, and DDQs.

## Audience

Software agents that need read-only access to an authorized AutoRFP.ai workspace: approved content, projects, requirements, and tags.

## Registration

1. Register an OAuth client at the authorization server registration endpoint.
2. Send the workspace user through Authorization Code with PKCE (S256).
3. Call the Streamable HTTP MCP endpoint with the access token in the Authorization header.
4. Request only the read scopes the agent needs. Existing workspace permissions still apply.

Public discovery documents do not require credentials. Workspace data does.

## Discovery documents

- Agent registration: https://autorfp.ai/auth.md
- OAuth authorization server: https://autorfp.ai/.well-known/oauth-authorization-server
- OAuth protected resource: https://autorfp.ai/.well-known/oauth-protected-resource
- MCP server card: https://autorfp.ai/.well-known/mcp/server-card.json
- Developer documentation: https://autorfp.ai/developers

## Authorization server

- Issuer: https://autorfp.ai
- Registration: https://api.autorfp.ai/register
- Authorization: https://api.autorfp.ai/authorize
- Token: https://api.autorfp.ai/token
- Revocation: https://api.autorfp.ai/revoke
- MCP: https://api.autorfp.ai/mcp

## Supported method

Anonymous dynamic client registration (`oauth_client`) at https://api.autorfp.ai/register. The authorization server accepts public clients and PKCE. It does not require a client secret.

## Scopes

- `tags:read`: Read the workspace tag vocabulary.
- `projects:read`: Read projects and their requirements.
- `content:read`: Search and read approved content and its usage.
