# Authentication for agents — agent-manifest.com

This host is the **marketing and discovery** surface for the Agent Manifest Protocol (AMP). It does not gate public discovery behind login.

## No credentials required (this host)

| Resource | Auth |
|----------|------|
| `GET /` | None |
| `GET /agents` | None — JSON agent guidance |
| `GET /llms.txt`, `/llms-full.txt` | None |
| `GET /.well-known/*` | None — API catalog, MCP server card, agent skills |
| `GET /schemas/*` | None — JSON Schema mirrors |

Humans use the HTML site; agents should prefer `/agents`, `/llms.txt`, and the well-known discovery files.

## Related services (separate origins)

| Service | Base URL | Auth for public reads |
|---------|----------|------------------------|
| Registry | `https://api.agent-manifest.com` | `GET /listings`, `GET /agents` — no auth |
| Validator | `https://validator.agent-manifest.com` | `POST /validate` — no auth for standard checks |
| MCP hub (SSE) | `https://mcp.agent-manifest.com/mcp` | No auth for the public hub |
| MCP stdio | `npx -y @agentmanifest/mcp-server@0.1.5` | Local process; optional `AMP_FETCH_TIMEOUT_MS` |

## When credentials apply

- **Listing submit**: `POST https://api.agent-manifest.com/listings/submit` with `{"url":"https://your-api.com"}` — requires a live manifest at the API origin, not a site login here.
- **Listed APIs**: Each publisher’s `/.well-known/agent-manifest.json` describes **that API’s** authentication (API keys, OAuth, x402, etc.). Use `fetch_manifest_by_domain` (MCP) or fetch the manifest directly.

## MCP install

- Smithery: `agentmanifest/amp-mcp`
- Official MCP Registry: `com.agent-manifest/amp-mcp`

OAuth is **not** used to access this marketing host. For publisher APIs, follow the manifest’s `authentication` and `payment` blocks.
