# Origo auth.md

Origo (https://origo-app.de) is a network for people: researchers and
practitioners who publish statements bound to the sources they rest on. Every
account belongs to one natural person.

## Audience

This file is for AI agents, bots, crawlers and other automated clients.

## Registration

Automated clients cannot register accounts, and there is no agent
registration endpoint. Do not create accounts through the registration form,
do not sign in with a member's password, and do not solve or bypass the
security check on the registration form. The terms of use allow accounts
only for people: https://origo-app.de/terms

## Acting for a member: the MCP connector

A member can connect an MCP client (an AI assistant) to their own account.
The member signs in on Origo and agrees on a consent page; the client then
reads in the member's name. This is OAuth 2.1:

- Authorization code flow with PKCE (S256); no implicit flow, no passwords.
- Dynamic client registration (RFC 7591): `POST https://origo-app.de/api/oauth/register`.
- Scope `posts:read`: search and read the posts the member may see, and
  members' profiles. Nothing can be posted or changed.
- Access tokens last one hour; refresh tokens change with each use. The
  member ends a connection at any time in the settings.

Metadata:

- Protected resource (RFC 9728): https://origo-app.de/.well-known/oauth-protected-resource/mcp
- Authorization server (RFC 8414): https://origo-app.de/.well-known/oauth-authorization-server
- MCP server card: https://origo-app.de/.well-known/mcp/server-card.json
- MCP endpoint (Streamable HTTP): https://origo-app.de/mcp

## Access without credentials

Without any account or token, agents may read:

- The MCP endpoint for public content: `https://origo-app.de/mcp/public`
- The public, read-only API:
  - `GET https://origo-app.de/api/public/posts/{id}`: a post its author made public
  - `GET https://origo-app.de/api/public/users/{handle}`: a profile its owner made public
  - `GET https://origo-app.de/api/public/stats`: public counts
  - `GET https://origo-app.de/api/health`: service status

Description: https://origo-app.de/openapi.json
Catalog: https://origo-app.de/.well-known/api-catalog
Documentation: https://origo-app.de/developers

## Credential use

Send an access token only as `Authorization: Bearer …` to
`https://origo-app.de/mcp`. Without a token, send no cookies and no
`Authorization` header. Name your tool and a contact address in the
`User-Agent` header and keep to about one request per second. Content that
is no longer public, or that the member can no longer see, must not be kept.

## Contact

The operator and its contact details are listed at https://origo-app.de/imprint
