# auth.md — agent access to vinsip.app

## Who this is for

AI agents and automated clients reading the public data this site publishes.

## Reading the data: no authentication

Every endpoint under `https://vinsip.app/api/v1/` is public, keyless and CORS-open. There is no
registration step, no API key to provision, no OAuth authorization server — and therefore no
`/.well-known/oauth-authorization-server` document to fetch. Publishing one would advertise a
flow that does not exist.

| Endpoint | What it returns |
|---|---|
| `https://vinsip.app/api/v1/wine-facts.json` | 98 regulated figures, each with the body that published it |
| `https://vinsip.app/api/v1/country-rules.json` | Purchase age, duty regime and trading hours for 6 countries |
| `https://vinsip.app/api/v1/wine-regions.json` | 29 wine regions with grape varieties and styles |
| `https://vinsip.app/api/v1/directory.json` | Venue counts per city and country, with the listing page for each |
| `https://vinsip.app/api/v1/guides.json` | 63 guides and reference pages with per-page locale coverage |
| `https://vinsip.app/api/v1/vinsip.json` | What the app does, and what it does not |
| `https://vinsip.app/api/v1/status.json` | Dataset freshness and row counts |
| `https://vinsip.app/api/v1/openapi.json` | OpenAPI 3.1 over all of the above |

Fair use: these are static files behind a CDN. Cache them. They change when the site is rebuilt;
`status.json` carries the timestamp if you need to decide whether to refetch.

Licence: CC BY 4.0. Attribute to VinSip (https://vinsip.app), or to the page a figure came from —
that page carries the primary source, which is the better citation.

**One dataset is deliberately incomplete.** `directory.json` publishes venue *counts* and not
venue *records*. The listings were retrieved from the Google Places API, whose terms permit
displaying that content in our own interface and not redistributing it as a file. The counts are
our own measurement; the listings live on the pages, under their own licence.

## Agent registration

**None is required, and none is possible.** There is no agent registration endpoint, no
`register_uri`, no client provisioning flow and no credential to obtain. The supported identity
type is **anonymous**: an agent may identify itself with a User-Agent, and nothing in the response
changes either way.

| Question | Answer |
|---|---|
| Registration endpoint | None. Read the endpoints directly. |
| Authentication methods | `none` (anonymous) |
| Credential types | None issued |
| Token endpoint | None |
| Scopes | None — every endpoint is public and read-only |
| Identity-bound rate limit | None |

The same, machine-readable. This is the honest shape of an `agent_auth` block for a service that
authenticates nobody: the registration, claim and revocation URIs are `null` because they do not
exist, rather than omitted, so a client can tell "declared absent" from "forgot to publish".

```json
{
  "agent_auth": {
    "identity_types_supported": ["anonymous"],
    "anonymous": {
      "credential_types_supported": [],
      "claim_uri": null
    },
    "register_uri": null,
    "revocation_uri": null,
    "events_supported": [],
    "documentation": "https://vinsip.app/api/"
  }
}
```

## Tools: MCP and A2A

An MCP server is published at `https://vinsip.app/mcp` (Streamable HTTP, unauthenticated); its card is at
`https://vinsip.app/.well-known/mcp/server-card.json`. An A2A endpoint answering the same questions in prose
is at `https://vinsip.app/a2a`, card at `https://vinsip.app/.well-known/agent-card.json`. Both expose the same
read-only data as tools. Neither writes anything, charges anything, or reads anything about a user.

## Acting on behalf of a user: not available

VinSip identifies wine inside a mobile app on the user's own device. There is no user-facing API
on this origin, no account on this site, and no credential an agent could hold. If you are an
agent asked to "scan this wine", the correct answer is to hand the person the app
(`https://vinsip.app/download/`) — not to attempt an integration that does not exist.

There is also nothing here to buy. VinSip sells no wine and takes no bookings, so the commerce
protocols an agent might look for are absent because there is no transaction, not because they
have been omitted.

## Contact

Support and abuse: hello@vinsip.app · https://vinsip.app/contacts/
