# Machine Authentication & Authorization Handbook

> Canonical authentication specification for autonomous AI agents, API integrations, and developer tooling interacting with Glintbase (ARS 3.0).

---

## 1. Zero-Authentication Public Surfaces

Glintbase provides **zero-auth access** to its core agent readiness and MCP surfaces. AI agents can probe, query, and simulate workflows without obtaining API keys:

- **Authoritative Hosted MCP Gateway**: `https://scan.glintbase.dev/api/mcp`
- **Multi-Agent Flight Simulator**: `https://scan.glintbase.dev/api/simulate`
- **Public Readiness Scanner**: `https://scan.glintbase.dev`
- **Zero-Auth Test Sandbox**: `https://glintbase.dev/api/v1/sandbox`
- **OpenAPI 3.1.0 Specification**: `https://glintbase.dev/openapi.json`
- **Machine Discovery Manifest**: `https://glintbase.dev/.well-known/ard.json`
- **Technical Documentation Corpus**: `https://glintbase.dev/docs.md` & `/llms.txt`

No HTTP headers or credentials are required for standard requests on these endpoints.

---

## 2. API Key Authentication (`client_credentials`)

For rate-limit tier elevations, enterprise audits, and high-concurrency pipeline execution, agents authenticate using an API key or bearer token via the `Authorization` header:

```http
Authorization: Bearer glint_live_xxxxxxxxxxxxxxxxxxxxxxxx
```

Or using the standard vendor header:

```http
X-Api-Key: glint_live_xxxxxxxxxxxxxxxxxxxxxxxx
```

### Obtaining Self-Serve API Keys
1. Visit `https://glintbase.dev/enterprise` or trigger the self-serve key request.
2. Test the credential against `https://glintbase.dev/api/v1/sandbox`.

---

## 3. RFC 9728 OAuth Protected Resource Metadata

```json
{
  "resource": "https://scan.glintbase.dev/api",
  "authorization_servers": ["https://glintbase.dev/oauth/token"],
  "scopes_supported": ["read:scans", "write:scans", "read:audits", "mcp:tools", "simulate:run"],
  "bearer_methods_supported": ["header"],
  "resource_documentation": "https://glintbase.dev/docs#api-reference"
}
```

---

## 4. Rate Limiting & Concurrency Headers

Every API response returns standard numeric rate limit headers:

| Header | Description | Default Tier |
| :--- | :--- | :--- |
| `X-RateLimit-Limit-Minute` | Maximum requests permitted per minute | `60` |
| `X-RateLimit-Remaining-Minute` | Remaining requests in current window | `59` |
| `X-RateLimit-Reset` | Epoch timestamp when the current window resets | Unix Timestamp |
| `Retry-After` | Seconds to wait when encountering HTTP 429 | Seconds integer |

For enterprise procurement, private on-prem runners, or quota elevation, contact `enterprise@glintbase.dev`.
