# auth.md

Agent authentication and registration information for `vpsticker.com`.

## Summary

This service is **public and read-only**. It has no user accounts, no login, no write
endpoints, and no per-caller quota. **No credentials are required to read anything on this
site**, and there is nothing here to register for.

This file exists because agent-facing discovery documents should state their authentication
posture explicitly, including when the answer is "none".

## Audience

AI agents, crawlers, and automated research tools that need VPS pricing in a machine-readable form.

## Resources

| Resource | Path | Auth |
|---|---|---|
| Price snapshot (JSON) | `/dataset/vpsticker-vps-prices.json` | none |
| Price snapshot (CSV) | `/dataset/vpsticker-vps-prices.csv` | none |
| Fetch outcomes (CSV) | `/dataset/fetch-status.csv` | none |
| Capability manifest | `/.well-known/ai-catalog.json` | none |
| Agent skill | `/.well-known/agent-skills/vps-price-data/SKILL.md` | none |
| Human-readable sources | `/sources` | none |

Currently serving 29 live offers across 15 tracked
providers.

## Supported methods

### anonymous

There is no registration step, no credential to obtain, and no provisioning endpoint to
call. Send an unauthenticated HTTPS request. That is the whole flow.

- `identity_types_supported`: `["anonymous"]`
- `credential_types_supported`: `["none"]`

## Agent registration {#agent-registration}

There is no registration process to document. No endpoint on this site creates an account,
issues a token, sends mail, or provisions a tenant. Do not attempt to register an agent
here; there is nothing to register against.

If a future version of this service adds authenticated resources, this file will document
the real registration flow and the authorization server will publish matching metadata at
`/.well-known/oauth-authorization-server`.

## Credential use

No credentials are issued, so there are none to present and none to protect. If you are
sending a credential to this host, it did not come from here and is not needed.

## OAuth metadata

- Protected resource metadata: `/.well-known/oauth-protected-resource`
- Authorization server metadata: `/.well-known/oauth-authorization-server`

Both documents are published and mutually consistent. They describe the absence of an
authorization requirement rather than a working token issuance flow, because the latter
does not exist here.

## Scope

- No authentication endpoints are probed or exercised by this site.
- No personal data is collected from agents or visitors. See `/privacy`.
- Requests are logged in aggregate by the CDN for security and capacity purposes only.

## Contact

Operated by one independent operator. Correspondence:
sanhu12138@outlook.com
