# majal.link auth.md

Agent registration and credential policy for `https://majal.link`, published for AI agents and other automated clients following the auth.md convention. This document is self-contained: Majal does not publish OAuth Authorization Server or Protected Resource metadata (see "Why there is no OAuth metadata" below).

## Audience

Automated clients: AI agents, crawlers, integrations and API tooling that want to read from or act on majal.link on behalf of a person or organisation.

## Summary

- **Public read access needs no credentials.** Profiles (`/p/{page}`), digital cards (`/c/{cardId}`), the blog, the sitemap and all discovery documents are open.
- **There is no public write API** and **no self-service agent registration.** Creating or editing profiles, cards, orders and analytics is only possible for the signed-in human account owner through the web application.
- **Agents must not drive the human login flows** (e-mail one-time code, Google or Facebook sign-in, payment). Those flows create accounts, send e-mail and issue credentials.
- Access beyond public reading is **provisioned manually by the Majal team** on request.

## Public resources (no credentials)

| Resource | URL |
| --- | --- |
| Profile page | `/p/{page}` |
| Digital business card | `/c/{cardId}` |
| Blog | `/ar/blog`, `/en/blog`, `/{lang}/blog/{slug}` |
| MCP server (read-only, no auth) | `/mcp` and `/.well-known/mcp/server-card.json` |
| API catalog (RFC 9727) | `/.well-known/api-catalog` |
| OpenAPI description | `/openapi.json` |
| Documentation | `/docs/api`, `/docs/api.md` |
| Health | `/health` |
| Sitemap / robots | `/sitemap.xml`, `/robots.txt` |

## Registration and provisioning

| | |
| --- | --- |
| Self-service registration endpoint | **None.** No `register_uri`, no dynamic client registration. |
| Provisioning channel | E-mail [contact@majal.link](mailto:contact@majal.link) or the form at [majal.link/contact](https://majal.link/contact), stating who operates the agent, which account(s) it should act for, and what it needs to do. |
| Supported registration methods | `manual` (operator-provisioned) only. |
| Not supported | `identity_assertion` (ID-JAG), `verified_email`, `anonymous`, OAuth dynamic client registration. |

Requests are reviewed by a person. Approved integrations receive instructions for their specific use case; nothing is issued automatically.

## Credential use

- The only credential the service issues today is a **browser session cookie named `token`** (a signed JWT). It is created when a human signs in at `/login` and is sent by the browser as a cookie; it is not accepted in an `Authorization` header and is not issued to automated clients.
- Session cookies are personal to the account owner. Do not extract, share or replay them from an automated client.
- No API keys, bearer tokens or OAuth access tokens are issued at this time. If that changes, this document and `/.well-known/api-catalog` will be updated first.

## Why there is no OAuth metadata

Majal signs its users in *with* Google and Facebook (it is an OAuth **client**), but it is not an OAuth **authorization server** and does not expose a token-protected resource API. Publishing `/.well-known/oauth-authorization-server` or `/.well-known/oauth-protected-resource` would therefore describe something that does not exist. Treat this file and the API catalog as the source of truth.

## Rules for agents

1. Follow `/robots.txt` and keep request rates modest.
2. Read only; never submit forms, one-time codes, OAuth callbacks or payments on a human's behalf.
3. Send a descriptive `User-Agent` with a contact URL or e-mail.
4. Cache discovery documents (they carry `Cache-Control: public, max-age=3600`).

## Contact

- E-mail: [contact@majal.link](mailto:contact@majal.link)
- Web: [https://majal.link/contact](https://majal.link/contact)
