# Automata auth.md

This document is for agents and API integrators using the Automata Waitlist API at `https://automata-ci.com/api/waitlist`.

## Registration and provisioning

- Public waitlist registration is available at `POST https://automata-ci.com/api/waitlist`. It creates a waitlist entry and does not issue credentials.
- Operator export credentials have no automated registration endpoint. They are manually provisioned by an Automata operator. Contact [sales@automata-ci.com](mailto:sales@automata-ci.com) to discuss authorized integration access.

The following machine-readable block describes the available non-OAuth provisioning method. The `register_uri` is a human-reviewed contact channel; it is not an automated HTTP registration endpoint.

```yaml
agent_auth:
  skill: "https://automata-ci.com/auth.md"
  register_uri: "mailto:sales@automata-ci.com"
  methods:
    - type: "manual_operator_provisioning"
      audience: "authorized Automata operators and integrations"
      credential_type: "opaque_bearer_token"
      bearer_method: "header"
```

## Supported methods

### Public registration

No authentication is required. Send an email address as JSON or form data:

```http
POST /api/waitlist HTTP/1.1
Host: automata-ci.com
Content-Type: application/json

{"email":"agent-owner@example.com"}
```

### Operator export

The export operation uses an opaque bearer token supplied in the HTTP `Authorization` header:

```http
GET /api/waitlist HTTP/1.1
Host: automata-ci.com
Authorization: Bearer <EXPORT_TOKEN>
```

Keep the token secret. Do not place it in URLs, query parameters, logs, browser code, or public agent configuration. A missing or invalid token returns HTTP 401.

## OAuth status

Automata does not currently operate an OAuth authorization server or a self-service agent registration flow. No OAuth Protected Resource Metadata is advertised. Clients must not infer OAuth endpoints that are not documented here.

See the [API documentation](https://automata-ci.com/api-docs) and [OpenAPI specification](https://automata-ci.com/openapi.json) for request and response details.
