# auth.md

Agent registration for [Království](https://www.kralovstvi.com/). You are an agent. This origin publishes a public menu, opening hours, and company facts. It does not create user accounts and it does not issue access tokens, API keys, or ID tokens.

The supported registration method is **anonymous**. You do not present an identity assertion, an email address, or a claim code. No credential is issued. Public reads already succeed with no `Authorization` header.

## Audience

Agents fetching the bilingual menu, site status, or company facts. There is no signed-in user to register on behalf of.

## Supported method

| Field | Value |
| --- | --- |
| Identity type | `anonymous` |
| Credential type | `none` |
| `register_uri` | `https://www.kralovstvi.com/agent/auth/register` |
| `claim_uri` | `https://www.kralovstvi.com/agent/auth/claim` |
| Revocation | Not applicable. Nothing is issued, so there is no `revocation_uri`. |

`credential_types_supported` is `["none"]`: this origin does not issue a bearer token or an API key. The scope name `public` in protected-resource metadata names those same unauthenticated reads.

## Registration

1. Fetch protected-resource metadata: [https://www.kralovstvi.com/.well-known/oauth-protected-resource](https://www.kralovstvi.com/.well-known/oauth-protected-resource). Read `resource`, `authorization_servers`, `scopes_supported`, and `bearer_methods_supported`.
2. Fetch authorization-server metadata for that issuer: [https://www.kralovstvi.com/.well-known/oauth-authorization-server](https://www.kralovstvi.com/.well-known/oauth-authorization-server). Read the `agent_auth` block (`skill`, `register_uri`, `identity_types_supported`, `anonymous.credential_types_supported`, `claim_uri`).
3. `GET` the `register_uri`. The JSON restates this anonymous registration result: access is already public and no credential is returned. Do not `POST` an identity assertion, email, or claim code. Do not probe the URL during a passive scan.
4. Read the resources. `GET /menu.json` and `GET /api/status.json` with no `Authorization` header.

`bearer_methods_supported` lists `header` because that is where a bearer token would be sent if this origin issued one. It does not. `grant_types_supported` is empty. `GET /oauth/authorize` returns `access_denied`. `GET /oauth/token` returns `unsupported_grant_type`.

### Claim

`claim_uri` is published because the anonymous method names a claim URL. There is no account to claim and no user code to show. `GET` the URL for that policy. Do not start a browser ceremony.

### Revocation

No revocation URL is published. There is no access token, identity assertion, or stored agent registration to revoke.

## Field names

`agent_auth` uses the isitagentready Auth.md names: `register_uri`, `claim_uri`, `identity_types_supported`, and `anonymous.credential_types_supported`. The [WorkOS auth.md file format](https://workos.com/auth-md) calls those positions `identity_endpoint` and `claim_endpoint`. Those names are omitted here. The WorkOS agent-verified and user-claimed ceremonies need user accounts and a credential this pub does not issue.

## Credential use

Send no `Authorization` header. A token is not required, and these static responses do not inspect one. Reservations are not an API: call +420 603 476 997.

## Discovery

- These instructions: [https://www.kralovstvi.com/auth.md](https://www.kralovstvi.com/auth.md)
- Protected resource: [https://www.kralovstvi.com/.well-known/oauth-protected-resource](https://www.kralovstvi.com/.well-known/oauth-protected-resource)
- Authorization server: [https://www.kralovstvi.com/.well-known/oauth-authorization-server](https://www.kralovstvi.com/.well-known/oauth-authorization-server)
- API docs: [https://www.kralovstvi.com/api/docs.md](https://www.kralovstvi.com/api/docs.md)
