# auth.md — YOTRON Agent Registration & Authentication

---
title: "auth.md — YOTRON Agent Registration & Authentication"
description: "Agent registration, authentication, and access protocols for autonomous AI agents interacting with YOTRON (優創智能)."
canonical: "https://yotron-ai.com/auth.md"
last-updated: "2026-08-24"
---

## Overview
This document defines the agent registration, authentication, and access protocols for autonomous AI agents and automated systems interacting with YOTRON (優創智能股份有限公司).

## Agent Audience
- Autonomous coding agents (Claude Code, Cursor, OpenCode, Codex)
- AI Search & Answer Engines (Perplexity, ChatGPT, Claude-Web)
- Business & Workflow AI Agents (Lark bots, n8n workflows, CRM automation)

## Agent Registration & Provisioning
- **Registration URI / Endpoint**: `POST https://yotron-ai.com/api/lead`
- **Supported Identity Types**: `anonymous`, `identity_assertion`
- **Supported Assertion Types**: `urn:ietf:params:oauth:token-type:id-jag`, `verified_email`
- **Claim URI / Endpoint**: `https://yotron-ai.com/api/lead`
- **Revocation URI**: `https://yotron-ai.com/api/lead`
 - **Supported Events**: `revocation`
 - **Supported Credential Types**: `bearer_token`
 
 ### Self-Serve Onboarding & Sandbox Testing
 - **Zero Friction**: AI agents and developers can interact with public endpoints immediately without manual sales outreach or waiting for account approval.
 - **Self-serve key generation**: no API key generation is required for the public trial; `apiKeyRequired: false` is returned by the sandbox status endpoint. Agents can start with zero-auth validation and request production access only after user confirmation.
 - **Instant Sandbox Mode**: Send `POST https://yotron-ai.com/api/lead?sandbox=true` or include the HTTP header `X-Sandbox: true` to test the full consultation intake pipeline with immediate JSON validation.
 - **Sandbox discovery**: `GET https://yotron-ai.com/sandbox` returns a zero-auth availability document; `POST https://yotron-ai.com/sandbox` is a no-side-effect smoke test.
 - **Versioned sandbox**: `GET https://yotron-ai.com/api/v1/lead?sandbox=true` confirms the versioned zero-auth surface before a POST validation.
 - **Public Read Endpoints**: `/llms.txt`, `/llms-full.txt`, `/sitemap.md`, `/openapi.json`, and all `/.well-known/*` metadata endpoints require no authentication.
 
 ### Machine-Readable Scopes
 - `read:content`: Access public knowledge bases, pricing tables, case studies, and glossary.
 - `write:lead`: Submit consultation requests, project requirements, and lead inquiries.
 - `read:catalog`: Query detailed service package deliverables, tiers, and execution timelines.
 
 ### Registration Method 1: Anonymous Access
- **Method**: Free read and consultation submission without pre-shared keys.
- **Header**: Optional `Authorization: Bearer <anonymous-token>`
- **Endpoint**: `POST https://yotron-ai.com/api/lead`
- **Content**: Plain JSON payload `{ "name": "Agent Name", "email": "agent@domain.com", "need": "Consultation Request" }`

### Registration Method 2: Identity Assertion (ID-JAG & Verified Email)
- **Token Type**: `urn:ietf:params:oauth:token-type:id-jag`
- **Credential Format**: Standard Bearer token supplied in the HTTP `Authorization: Bearer <token>` header.
- **Scopes**: `read:content`, `write:lead`, `read:catalog`

## Machine-Readable Discovery Endpoints
- **OAuth Protected Resource (PRM)**: `https://yotron-ai.com/.well-known/oauth-protected-resource`
- **OAuth Authorization Server**: `https://yotron-ai.com/.well-known/oauth-authorization-server`
- **OpenID Configuration**: `https://yotron-ai.com/.well-known/openid-configuration`
- **Agent Skills Index**: `https://yotron-ai.com/.well-known/agent-skills/index.json`
- **Agent Authentication Skill**: `https://yotron-ai.com/.well-known/agent-skills/consultation-inquiry/SKILL.md`
- **Developer Resources**: `https://yotron-ai.com/developers`
- **MCP Server Card**: `https://yotron-ai.com/.well-known/mcp/server-card.json`
- **API Catalog (RFC 9727)**: `https://yotron-ai.com/.well-known/api-catalog`
- **A2A Agent Card**: `https://yotron-ai.com/.well-known/agent-card.json`
- **ARD Capability Manifest**: `https://yotron-ai.com/.well-known/ai-catalog.json`

## Permissions, Rate Limits & Content Signals
- **Content Signals**: `Content-Signal: search=yes, ai-input=yes, ai-train=no`. Public search and answer retrieval are allowed; model training is not.
- **Rate Limit**: 60 requests per minute per IP.
- **Contact & Support**: info@yotron-ai.com
