# auth.md — infyicon.com

Agent registration for infyicon.com (161,000+ free icons (SVG/PNG) with attribution, MCP server, plugins for Figma/Canva/Office/etc.).

- **Agent audience:** any AI agent, crawler or automated client (MCP clients, A2A agents, scripts).
- **Identity types supported:** anonymous — no human account is needed or created (auth.md "anonymous" registration method).
- **Registration endpoint (register_uri):** POST https://infyicon.com/oauth/register — OAuth 2.0 dynamic client registration (RFC 7591), no initial token needed.
- **Claim endpoint (claim_uri):** https://infyicon.com/oauth/register (anonymous clients are complete at registration; nothing to claim).
- **Supported methods:** client_credentials (recommended) and authorization_code + PKCE S256 (one-click consent page, no login).
- **Credential use:** send the access token as Authorization: Bearer <token> to https://infyicon.com/mcp, https://infyicon.com/a2a and https://infyicon.com/api/*
- **Revocation:** discard the client_secret and register again (tokens expire after 1 hour).

## What the token is for

Public reading of the catalogue works **without any credentials**. A token only identifies your agent and lifts the
anonymous rate limit (60 → 600 requests/min per IP) on the agent endpoints. It never grants purchases, paid downloads or
personal data. Buying: All icons are free with a visible attribution link (see /license); Premium removes attribution.

## Discovery documents

- Authorization-server metadata (RFC 8414): https://infyicon.com/.well-known/oauth-authorization-server
- Protected-resource metadata (RFC 9728): https://infyicon.com/.well-known/oauth-protected-resource
- JWKS: https://infyicon.com/oauth/jwks
- API catalog: https://infyicon.com/.well-known/api-catalog — OpenAPI: https://infyicon.com/openapi.json
- Agent card (A2A): https://infyicon.com/.well-known/agent-card.json — Skills: https://infyicon.com/.well-known/agent-skills/index.json
- ARD manifest: https://infyicon.com/.well-known/ai-catalog.json
- MCP server card: https://infyicon.com/.well-known/mcp/server-card.json (endpoint https://infyicon.com/mcp)

## agent_auth (same block as in the authorization-server metadata)

```json
{
  "skill": "https://infyicon.com/auth.md",
  "register_uri": "https://infyicon.com/oauth/register",
  "identity_types_supported": [
    "anonymous"
  ],
  "anonymous": {
    "credential_types_supported": [
      "oauth2_client_credentials",
      "oauth2_authorization_code_pkce"
    ],
    "claim_uri": "https://infyicon.com/oauth/register"
  },
  "token_endpoint": "https://infyicon.com/oauth/token",
  "scopes_supported": [
    "catalog:read",
    "agent:identify"
  ],
  "events_supported": [
    "client.registered",
    "token.issued"
  ]
}
```

## Register + get a token (anonymous flow)

Step 1 — register (register_uri):

    POST https://infyicon.com/oauth/register
    Content-Type: application/json

    {"client_name": "My shopping agent", "grant_types": ["client_credentials"], "token_endpoint_auth_method": "client_secret_post"}

Response 201: {"client_id": "agent_…", "client_secret": "…"} — store both; the secret is shown once.

Step 2 — token:

    POST https://infyicon.com/oauth/token
    Content-Type: application/x-www-form-urlencoded

    grant_type=client_credentials&client_id=agent_…&client_secret=…&scope=catalog:read

Response: {"access_token": "<RS256 JWT>", "token_type": "Bearer", "expires_in": 3600} — verify with the JWKS if you proxy it.

Scopes: catalog:read (search/read the catalogue), agent:identify (identity only).
Public clients may register with "token_endpoint_auth_method": "none" and must then use the authorization-code flow with PKCE:
GET https://infyicon.com/oauth/authorize?response_type=code&client_id=…&redirect_uri=…&code_challenge=…&code_challenge_method=S256&scope=catalog:read

## Rules

- Respect robots.txt (Content-Signal: ai-train=no, search=yes, ai-input=yes) and llms.txt.
- Don't scrape preview images in bulk; use the catalogue index / MCP tools.
- Contact: info@infyicon.com
