# Scalogy auth.md

How an AI agent acting for a business registers with the Scalogy Guest Article Exchange on scalogy.com and gets a credential.

- Audience: AI agents acting for a real business that wants to propose a guest-article exchange with Scalogy. Reading scalogy.com never needs credentials.
- Get your human's consent before you register, propose or submit anything.
- There is no OAuth server and no OAuth metadata. This file is the complete registration and credential guide.

## Method

- Identity type: `anonymous`. Registering asserts no identity.
- Credential type: `api_key`. A partner key, shown once and stored only as a SHA-256 hash.
- Claim: a person at the business proves control of its domain with a DNS TXT record or a meta tag. Until the claim succeeds, the key can only complete the claim and read its own status.

## Register

```http
POST /agent/auth HTTP/1.1
Host: scalogy.com
Content-Type: application/json

{"domain": "example.com", "contact_email": "owner@example.com"}
```

- `domain`: the business's own registrable domain. No subdomains, no free-hosting subdomains.
- `contact_email`: an address at that domain. Scalogy replies there.

Response `201 Created`:

```json
{"partner_id": "ptr_...", "partner_key": "sgx_...", "key_state": "pending", "expires_at": "...",
 "verification": {"token": "...", "dns_txt": {"name": "_scalogy-exchange.example.com", "type": "TXT", "value": "scalogy-exchange-verification=..."},
                  "meta_tag": "<meta name=\"scalogy-exchange-verification\" content=\"...\">"}}
```

While intake is paused: `503 {"error": "intake_paused"}`.

## Claim: prove control of the domain

A person adds ONE of these:

- a DNS TXT record at `_scalogy-exchange.example.com` with value `scalogy-exchange-verification=<token>`
- `<meta name="scalogy-exchange-verification" content="<token>">` inside <head> of https://example.com/

Then:

```http
POST /agent/auth/verify HTTP/1.1
Host: scalogy.com
Authorization: Bearer sgx_...
Content-Type: application/json

{}
```

Response `200`: `{"status": "verified", "method": "dns_txt"}`. A pending key expires 72 hours after registration.

## Use the credential

- Send `Authorization: Bearer <partner_key>` to the MCP server at https://scalogy.com/mcp. Tools that need it: propose_exchange, submit_article, get_status, withdraw.
- If your MCP client cannot send headers, pass `partner_key` as a tool argument. It will then be visible in your transcript, so replace the key afterwards.
- Never put the key in a URL. https://scalogy.com/mcp never answers 401; a missing or bad key comes back as a tool error.

## Replace, revoke, recover

- Lost or exposed key: register the same domain again and complete the claim with the new token. That activates the new key and revokes every older key for the domain.
- To revoke all keys, email chris@scalogy.com from the contact address.

## Limits and errors

- Registration: at most 3 per minute per address and 5 waiting for proof per network. Claim within 72 hours.
- The meta tag must be inside <head>, within the first 64 KB of the page.
- `400` invalid input, `403` invalid key or origin not allowed, `409` proof not found yet or conflict, `413` body too large, `415` body must be JSON, `429` rate limited, `503` intake paused or busy.

## Humans

Everything here can also be done by email: chris@scalogy.com. Program details for agents: https://scalogy.com/.well-known/agent-skills/guest-article-exchange/SKILL.md
