# Auth — Dony.app

How agents authenticate to the Dony.app Agent API.

## What needs no key

These endpoints are public (rate-limited by platform defaults):

- `GET https://donyapp.com/api` — API catalog index (machine-readable)
- `GET https://donyapp.com/api/v1` — v1 route list
- `GET https://donyapp.com/api/v1/health`
- `GET https://donyapp.com/api/v1/product`
- `GET https://donyapp.com/api/v1/features`
- `GET https://donyapp.com/api/v1/pricing`
- `GET https://donyapp.com/openapi.json` (alias: `GET https://donyapp.com/api/openapi.json`)
- `GET https://donyapp.com/.well-known/mcp.json`
- MCP tools `get_product`, `get_features`, `get_pricing`, `get_health` via `POST https://donyapp.com/api/mcp`
- MCP Apps UI resources under `ui://donyapp/*.html` via `resources/list` and `resources/read`
- WebMCP tools on the homepage (same catalog actions via `document.modelContext`)

Public responses never include customer jobs, contacts, or delivery links.

Errors on `/api/*` Agent routes return JSON:

```json
{ "error": { "code": "unauthorized", "message": "…", "status": 401, "resolution": "…" } }
```

## OAuth 2.0 (authorization code + PKCE S256)

1. Read authorization server metadata: [`/.well-known/oauth-authorization-server`](https://donyapp.com/.well-known/oauth-authorization-server)
2. Read protected resource metadata (scopes): [`/.well-known/oauth-protected-resource`](https://donyapp.com/.well-known/oauth-protected-resource)
3. Register a public client: `POST https://donyapp.com/oauth/register` with `redirect_uris`
4. Send the human to `GET https://donyapp.com/oauth/authorize` with `response_type=code`, `client_id`, `redirect_uri`, `scope`, `state`, `code_challenge`, `code_challenge_method=S256`
5. Exchange the code at `POST https://donyapp.com/oauth/token` (`grant_type=authorization_code` + `code_verifier`)
6. Call protected routes with `Authorization: Bearer <access_token>`

### Scopes

- `product:read` — Read public product, features, and pricing catalog
- `profile:read` — Read the authenticated user's profile summary
- `account:read` — Read the authenticated user's studio account summary

### Protected routes

- `GET https://donyapp.com/api/v1/me` — requires `profile:read`
- `GET https://donyapp.com/api/v1/account` — requires `account:read`
- MCP tools `get_my_profile` / `get_my_account` — same scopes

### Refresh

`POST https://donyapp.com/oauth/token` with `grant_type=refresh_token` and `refresh_token`.

## OpenAPI

Full schema: [https://donyapp.com/openapi.json](https://donyapp.com/openapi.json)

API catalog: [https://donyapp.com/api](https://donyapp.com/api)

## MCP

Manifest: [https://donyapp.com/.well-known/mcp.json](https://donyapp.com/.well-known/mcp.json)

Streamable HTTP: `POST https://donyapp.com/api/mcp`
