# Chess4pro auth.md

## Overview
Authentication and registration contract for autonomous AI agents, personal shoppers, and programmatic callers interacting with Chess4pro.

## Agent Audience
This service supports autonomous commerce agents adhering to the Universal Commerce Protocol (UCP), Agentic Commerce Protocol (ACP), and Model Context Protocol (MCP).

## Registration Flow

```json
{
  "agent_auth": {
    "skill": "https://chess4pro.online/.well-known/agent-skills/shopping/SKILL.md",
    "register_uri": "https://chess4pro.online/api/ucp/register",
    "identity_types_supported": ["anonymous", "identity_assertion"],
    "anonymous": {
      "claim_uri": "https://chess4pro.online/api/ucp/claim",
      "credential_types_supported": ["bearer_token", "api_key"]
    },
    "identity_assertion": {
      "claim_uri": "https://chess4pro.online/api/ucp/claim",
      "assertion_types_supported": ["verified_email", "urn:ietf:params:oauth:token-type:id-jag"],
      "credential_types_supported": ["bearer_token"]
    },
    "revocation_uri": "https://chess4pro.online/api/ucp/revoke",
    "events_supported": ["revocation"]
  }
}
```

## Standalone Registration Instructions
To register an autonomous agent with Chess4pro:
1. Registration Endpoint: POST https://chess4pro.online/api/ucp/register with agent client metadata and callback.
2. Claim Endpoint: POST https://chess4pro.online/api/ucp/claim with user assertion or anonymous token.
3. Supported Identity Types: anonymous, identity_assertion (verified_email, id-jag).
4. Supported Credentials: Bearer API tokens for shopping sessions.
5. Revocation: POST https://chess4pro.online/api/ucp/revoke to terminate agent delegation.

## OAuth Protected Resource Metadata
```json
{
  "resource": "https://chess4pro.online",
  "authorization_servers": ["https://shopify.com/authentication/27775074368"],
  "scopes_supported": ["read_products", "read_content", "create_cart", "checkout"],
  "bearer_methods_supported": ["header"]
}
```
