# datajoi auth.md

Authentication and agent-registration documentation for **datajoi.com** and the
datajoi platform. This document is self-contained: datajoi does not currently
operate an OAuth authorization server, so no OAuth Protected Resource Metadata
or Authorization Server Metadata is published. What is written here is the
complete, authoritative story — agents should not probe for undocumented
endpoints.

## Who this is for

Automated agents (crawlers, assistants, MCP clients) that want to interact with
datajoi on behalf of a user. Today the agent-usable surface of datajoi.com is:

- `GET /llms.txt` — plain-language site summary
- `GET /.well-known/api-catalog` — RFC 9727 API catalog
- `GET /api/openapi.json` — OpenAPI 3.1 description
- `GET /api/` — human-readable API documentation
- `GET /api/health` — liveness probe (safe to call)
- `GET /sitemap.xml` — public page list

All of the above are anonymous and require no credentials.

## Authentication today

- **datajoi.com (this site)** has no authenticated endpoints. The only write
  endpoint, `POST /api/lead`, is protected by an interactive Cloudflare
  Turnstile challenge and is therefore effectively human-gated. It issues no
  credentials.
- **The datajoi platform app** (`https://platform.datajoi.com`) is gated by
  Cloudflare Access with an interactive sign-in. There is **no public OAuth
  authorization server, no token endpoint, no dynamic client registration, and
  no API-key issuance**. Agents cannot authenticate to it programmatically.

## Registration / provisioning

Access to the datajoi platform is provisioned by humans, for humans:

1. A person submits the early-access form at
   `https://datajoi.com/platform/#cta` (or emails `hello@datajoi.com`).
2. The datajoi team reviews the request and provisions an account on the
   platform, granting sign-in via Cloudflare Access.
3. No API credentials, tokens, or agent identities are issued as part of this
   flow today.

Agents assisting a user with registration should hand off to the form or draft
the email — do not attempt to POST to `/api/lead` autonomously; the Turnstile
requirement will reject the request.

## Future

When the datajoi platform ships a public API with a real authorization server,
this document will be updated and OAuth Protected Resource Metadata will be
published at `/.well-known/oauth-protected-resource`, with Authorization Server
Metadata (including an `agent_auth` registration block) at the advertised
issuer. Until those documents exist, assume programmatic authentication is
unavailable.

## Contact

Questions about agent access: `hello@datajoi.com`.
