Agent identity is provided by WorkOS AuthKit. The authorisation server and scopes are published in /.well-known/oauth-protected-resource (RFC 9728); step-by-step commands are in /auth.md.
Steps
- Reuse a registration if you have one. Do not register again for every task.
- Register.
anonymousneeds no email and grantswaitlist:writeandsurvey:writeat once.service_authtakes the person's email and needs the claim step. - Claim (for
service_auth; optional foranonymous). You give the person a link; they sign in and read you a code; you complete the claim with it. Their identity is then attached to your token, and submissions aretrusted. - Exchange the registration's assertion for an access token (
grant_typeJWT bearer) at the authorisation server's token endpoint.
Store secrets in the operating system's credential store and never print them.
Using the token
Send Authorization: Bearer <token>.
- No token:
401with aWWW-Authenticateheader pointing to the protected resource metadata. - Valid token without the scope:
403. - Expired token: exchange the assertion again; if the assertion has expired too, register again.
Scopes
| Scope | Allows |
|---|---|
waitlist:write | One agent waiting-list entry per registration |
survey:write | One survey per registration |