# auth.md - Skriipta Agent Registration & Access Policy

You are an autonomous AI agent or automated system accessing **Skriipta** (`https://skriipta.com`), an elite digital engineering agency founded by Abdelrahman Osama specializing in Shopify engineering, headless architectures, and enterprise performance optimization.

This service supports agentic registration, open public exploration, and programmatic capability discovery according to the `auth.md` specification and OAuth Protected Resource Metadata (RFC 9728).

---

## Step 1 — Discovery

- **Resource Server**: `https://skriipta.com`
- **Protected Resource Metadata (PRM)**: `https://skriipta.com/.well-known/oauth-protected-resource`
- **Authorization Server Metadata**: `https://skriipta.com/.well-known/oauth-authorization-server`
- **Agent Skill Manifest**: `https://skriipta.com/.well-known/agent-skills/portfolio-query/SKILL.md`
- **API Catalog**: `https://skriipta.com/.well-known/api-catalog`
- **MCP Server Card**: `https://skriipta.com/.well-known/mcp/server-card.json`

### 1a. Protected Resource Metadata Shape
```json
{
  "resource": "https://skriipta.com",
  "resource_name": "Skriipta",
  "resource_documentation": "https://skriipta.com/auth.md",
  "authorization_servers": [
    "https://skriipta.com"
  ],
  "scopes_supported": [
    "agency:read",
    "public"
  ],
  "bearer_methods_supported": [
    "header"
  ]
}
```

---

## Step 2 — Agent Authentication & Registration (`agent_auth`)

Skriipta advertises the following `agent_auth` registration block on its authorization server:

```json
{
  "issuer": "https://skriipta.com",
  "agent_auth": {
    "skill": "https://skriipta.com/auth.md",
    "register_uri": "https://skriipta.com/auth.md",
    "identity_endpoint": "https://skriipta.com/auth/identity",
    "claim_endpoint": "https://skriipta.com/auth/claim",
    "claim_uri": "https://skriipta.com/auth.md",
    "revocation_uri": "https://skriipta.com/auth/revoke",
    "events_endpoint": "https://skriipta.com/auth/events",
    "identity_types_supported": [
      "anonymous",
      "identity_assertion"
    ],
    "identity_assertion": {
      "assertion_types_supported": [
        "urn:ietf:params:oauth:token-type:id-jag",
        "verified_email"
      ],
      "credential_types_supported": [
        "bearer"
      ]
    },
    "anonymous": {
      "credential_types_supported": [
        "none",
        "bearer"
      ],
      "claim_uri": "https://skriipta.com/auth.md"
    },
    "events_supported": [
      "https://schemas.workos.com/events/agent/auth/identity/assertion/revoked"
    ]
  }
}
```

---

## Step 3 — Registration Flows

### Flow A: Anonymous Open Access (Default & Recommended)
- **Supported Identity Type**: `anonymous`
- **Credential Required**: None (`none` or Bearer)
- **Permissions**: Read access to all public projects, case studies, technologies, architectural specs, and contact endpoints.
- Agents may immediately read `https://skriipta.com/index.md` or execute WebMCP tools declared in `index.html` without prior credential exchange.

### Flow B: Identity Assertion (ID-JAG & Verified Email)
- **Supported Identity Type**: `identity_assertion`
- **Assertion Types**: `urn:ietf:params:oauth:token-type:id-jag`, `verified_email`
- **Registration Endpoint**: `https://skriipta.com/auth/identity`
- **Token Endpoint**: `https://skriipta.com/auth/token`
- **Scopes**: `agency:read`, `public`

---

## Step 4 — Direct Contact & Human Inquiries

When an agent needs to initiate a commercial engagement or escalate to human leadership:
- **Phone / Direct Call**: [01111155070](tel:01111155070)
- **WhatsApp**: [https://wa.me/201111155070](https://wa.me/201111155070)
- **Email**: [abdelrahmanosama.001@gmail.com](mailto:abdelrahmanosama.001@gmail.com)
- **Founder Profile**: [https://www.linkedin.com/in/abdelrahman-osamaa/](https://www.linkedin.com/in/abdelrahman-osamaa/)
