# Authentication

The Directory News public API, MCP server, A2A endpoint and NLWeb `/ask` endpoint are **anonymous and read-only**. There is no `agent_auth` block, no `identity_endpoint`, no API key and no OAuth flow, because there is nothing to protect: every response mirrors a public page.

## Discover

- OpenAPI description: https://thedirectorynews-staging.vercel.app/openapi.json
- API catalog (RFC 9727): https://thedirectorynews-staging.vercel.app/.well-known/api-catalog
- Resource catalog (ARD): https://thedirectorynews-staging.vercel.app/.well-known/ard.json
- MCP server: https://thedirectorynews-staging.vercel.app/mcp (server card: https://thedirectorynews-staging.vercel.app/.well-known/mcp/server-card.json)
- A2A agent card: https://thedirectorynews-staging.vercel.app/.well-known/agent-card.json
- Docs: https://thedirectorynews-staging.vercel.app/developers

## Pick a method

Supported identity type: `anonymous`. `identity_assertion` (including `id-jag`) and `service_auth` are not offered.

## Register, Claim, Exchange

Not applicable. There is no registration, claim step or token exchange, and no `access_token` is ever issued.

## Use the access_token

Not applicable. Send the request without an `Authorization` header. The server never answers 401, so it never sends a `WWW-Authenticate` challenge.

## Errors

Failures return JSON `{"error":{"code":"...","message":"...","hint":"...","docs":"/developers"}}`: 400 for a missing or invalid parameter, 404 for an unknown endpoint, 429 when the rate limit is exceeded (with `Retry-After`). Every API response carries `RateLimit-Limit`, `RateLimit-Remaining` and `RateLimit-Reset`; the limit is 60 requests per minute per client.

## Revocation

Nothing to revoke: no credential exists.

## Sandbox

The API only reads public data, so calling the live site is already safe; there is no state an agent can change.
