# Auth.md

How AI agents and clients authenticate against im-in.events. Resource metadata: `/.well-known/oauth-protected-resource`.

## Agent audience

AI agents reading public event pages, availability, and site documentation on behalf of users. Dashboard, claim, and participant-manage URLs are private surfaces and must not be indexed or summarized.

## Registration and provisioning

There is no agent self-registration endpoint today. Credentials are provisioned to humans only: organizers create an account in the browser with Firebase Auth (Google sign-in or email/password). An agent acting for an organizer must be handed a Firebase ID token obtained from that human session.

## Supported authentication methods

- None required for public reads: event pages (`/{userCode}/{eventSlug}`), `llms.txt`, `llms-full.txt`, `.md` page variants, `/.well-known/*`.
- Bearer token for protected organizer API routes: `Authorization: Bearer <Firebase ID token>` (issuer `https://securetoken.google.com/imin-9d718`). Public API routes document their own validation and limits.

## Credential usage

Send the Firebase ID token in the `Authorization` header on protected requests; tokens are short-lived and refreshed by the human session that issued them. Public signup forms are additionally protected by Cloudflare Turnstile, so automated participant signup is not supported. Agents helping a user join an event should hand the user the event URL.

The public MCP endpoint `/api/mcp` can list templates and create one rate-limited signup sheet using the user's real email address. The private claim link is emailed to that address and is never returned to the agent.

The MCP tool `draft_sheet_link` (input: `words`, the user's email, notes or description) needs no email and creates nothing. It returns a link; the same link can be built by hand: `https://im-in.events/?utm_source=agent&utm_medium=agent-link#describe=<the user's words, URL-encoded>` (the MCP tool's link says utm_source=mcp). It opens the sheet editor with those words already in the Describe it box. The user presses Make my draft, checks it, and publishes. It costs nothing until they press it.

## Anything else

Contact via the site footer. A human answers.
