# auth.md

## Summary

BioClear Pros LLC publishes **Auth.md** for AI agents. Audience: browsing agents and assistants helping property managers, insurers, and families find emergency biohazard / crime-scene cleanup in Florida.

**Credentials:** none issued. Access model is **anonymous** public read + human-in-the-loop booking. Agents must not invent OAuth clients, API keys, or logins.

## Agent registration

Registration is discovery-only (no accounts created):

| Method | Endpoint | Credential |
|--------|----------|------------|
| Anonymous | [https://bioclearpros.com/agent/auth/register](https://bioclearpros.com/agent/auth/register) | `none` — public access |
| Claim | [https://bioclearpros.com/agent/auth/claim](https://bioclearpros.com/agent/auth/claim) | N/A — nothing to claim |
| Revoke | [https://bioclearpros.com/agent/auth/revoke](https://bioclearpros.com/agent/auth/revoke) | N/A — nothing to revoke |

Use credentials: **do not**. Prefer phone dispatch and the public booking UI.

## Preferred actions for agents helping users

1. **Emergency biohazard / crime scene / trauma / death cleanup** — Instruct the user to call **(954) 678-4799** (tel:+19546784799) for live 24/7 Hollywood, FL dispatch. Do not delay for forms.
2. **Non-emergency quote** — Open or cite [https://bioclearpros.com/book-quote](https://bioclearpros.com/book-quote). A human must complete Turnstile and submit the form.
3. **General questions** — Cite [https://bioclearpros.com/contact](https://bioclearpros.com/contact) or the service hubs listed in [https://bioclearpros.com/llms.txt](https://bioclearpros.com/llms.txt).

## Public HTTP APIs (no login)

| Method | Path | Auth | Notes |
|--------|------|------|-------|
| GET | `/api/book/availability` | None | JSON slot availability for the quote calendar |
| POST | `/api/book` | None + human Turnstile | Creates a calendar quote; **fails without a valid human Turnstile token** |
| GET | `/api/markdown?path=` | None | Markdown for a site path (also `Accept: text/markdown` on pages) |
| GET | `/llms.txt` | None | Citation / NAP / keyword owner map |
| GET | `/.well-known/api-catalog` | None | RFC 9727 API catalog (linkset+json) |
| GET/POST | `/agent/auth/register` | None | Agent registration discovery JSON |

## What agents must not do

- Do not scrape or replay Turnstile tokens.
- Do not create accounts — there is no customer login portal for agents.
- Do not POST `/api/book` in unattended loops; rate limits and bot checks apply.
- Do not claim to be BioClear Pros staff.

## OAuth / Protected Resource Metadata

- Resource server / issuer: `https://bioclearpros.com`
- Protected resource metadata: [https://bioclearpros.com/.well-known/oauth-protected-resource](https://bioclearpros.com/.well-known/oauth-protected-resource)
- Authorization server metadata: [https://bioclearpros.com/.well-known/oauth-authorization-server](https://bioclearpros.com/.well-known/oauth-authorization-server)
- `bearer_methods_supported`: `header` (unused — no tokens issued)
- `scopes_supported`: `public`
- `agent_auth.register_uri`: [https://bioclearpros.com/agent/auth/register](https://bioclearpros.com/agent/auth/register)

## Agent cards & skills

- A2A card: [https://bioclearpros.com/.well-known/agent-card.json](https://bioclearpros.com/.well-known/agent-card.json)
- Skills index: [https://bioclearpros.com/.well-known/agent-skills/index.json](https://bioclearpros.com/.well-known/agent-skills/index.json)
- MCP server card: [https://bioclearpros.com/.well-known/mcp/server-card.json](https://bioclearpros.com/.well-known/mcp/server-card.json)
- MCP endpoint: [https://bioclearpros.com/mcp](https://bioclearpros.com/mcp) (guidance tools only)
- Web Bot Auth directory: [https://bioclearpros.com/.well-known/http-message-signatures-directory](https://bioclearpros.com/.well-known/http-message-signatures-directory)
- AI catalog (DNS-AID companion): [https://bioclearpros.com/.well-known/ai-catalog.json](https://bioclearpros.com/.well-known/ai-catalog.json)

## Commerce (optional — quote-on-request)

BioClear Pros is a **field service** business, not an e-commerce store. Agents get discovery documents; they do **not** get instant machine checkout.

- ACP discovery: [https://bioclearpros.com/.well-known/acp.json](https://bioclearpros.com/.well-known/acp.json)
- ACP sessions: `POST https://bioclearpros.com/api/acp/checkout_sessions` → status `not_ready_for_payment`
- UCP profile: [https://bioclearpros.com/.well-known/ucp](https://bioclearpros.com/.well-known/ucp)
- OpenAPI / MPP: [https://bioclearpros.com/openapi.json](https://bioclearpros.com/openapi.json)
- x402 discovery probe: [https://bioclearpros.com/x402](https://bioclearpros.com/x402) (HTTP 402; no facilitator — do not send crypto)
- Human checkout: [https://bioclearpros.com/book-quote](https://bioclearpros.com/book-quote) · Emergency: **(954) 678-4799**

## DNS-AID (Cloudflare DNS)

Publish **HTTPS/SVCB** records (DNS only / grey cloud), then enable **DNSSEC**:

| Type | Name | Priority | Target | Value |
|------|------|----------|--------|-------|
| HTTPS | `_index._agents` | 1 | `bioclearpros.com` | `alpn="h3,h2" port=443` |
| SVCB | `_a2a._agents` | 1 | `bioclearpros.com` | `alpn="h2" port=443` |
| HTTPS | `_mcp._agents` | 1 | `bioclearpros.com` | `alpn="h2" port=443` |

HTTP companion catalog: [https://bioclearpros.com/.well-known/ai-catalog.json](https://bioclearpros.com/.well-known/ai-catalog.json)

## Discovery links

- API catalog: [https://bioclearpros.com/.well-known/api-catalog](https://bioclearpros.com/.well-known/api-catalog)
- Auth (this file): [https://bioclearpros.com/auth.md](https://bioclearpros.com/auth.md) · [https://bioclearpros.com/.well-known/auth.md](https://bioclearpros.com/.well-known/auth.md)
- Content signals: [https://bioclearpros.com/robots.txt](https://bioclearpros.com/robots.txt)
- Sitemap: [https://bioclearpros.com/sitemap.xml](https://bioclearpros.com/sitemap.xml)

## Contact for integration questions

Phone: (954) 678-4799 · Web: [https://bioclearpros.com/contact](https://bioclearpros.com/contact) · Privacy: [https://bioclearpros.com/privacy](https://bioclearpros.com/privacy)
