# auth.md

How an agent authenticates with NomiCheck — and why it barely needs to.

## Audience

Software agents consuming the public API at https://nomicheck.ynt.codes (Colombian payslip
verification, legal catalog verified as of 2026-07-30).

## Registration: NONE

We issue no API keys, there are no agent accounts and no registration
endpoint. This is by design, not an omission: the API is used without an
identity, and paid operations are paid **per call**.

## Supported methods

- **Integration reads** (OpenAPI, schemas, signed examples, public key,
  legal parameters, health): **no credential at all.**
- **Paid operations** (e.g. the verification report, 0.02 USD per
  batch): **x402** — the server answers `HTTP 402` with the exact
  requirements (`accepts`: network, token, amount, `payTo` and the
  EIP-712 domain); the agent signs an **EIP-3009** authorization (USDC; the
  facilitator pays the gas) and retries with the payment attached. No
  account, no API key.
- Before signing, cross-check the `payTo` against the
  `x-executor.walletAddress` in
  https://ynt.codes/.well-known/agent-card.json — an x402 payment is final.

## Credential use

No credential is issued or accepted on the public API (no API keys, no
tokens, no client registration). `/.well-known/oauth-protected-resource`
exists with `authorization_servers` **empty** — which is the truth: no
issuer emits tokens for this resource. What this domain does **not** publish
is `/.well-known/openid-configuration` or `oauth-authorization-server`:
that would declare
an issuer that does not exist, and it would be lying to whoever reads it.

The session portals (`/empresa`, `/colaborador`, `/admin`) are for
people, use Supabase Auth, and are **not agent surface** — robots.txt
excludes them.

## Getting started

One GET answers what this is, what is free and how to verify the output
without trusting us: GET https://nomicheck.ynt.codes/api/batch/quickstart
