# auth.md

Jasvel's machine surface is **anonymous and read-only**. There is nothing to register for,
nothing to authenticate with, and no credential that would grant more than an unauthenticated
request already gets.

| | |
|---|---|
| Identity type | `anonymous` |
| `register_uri` | `null` — there is no registration endpoint |
| `claim_uri` | `null` |
| `revocation_uri` | `null` |
| Authorization servers | none |
| Rate limit | none |
| Cost | none |

## Why there is no registration flow

Every endpoint is a static JSON file or a read-only computation over published rule tables.
Nothing is written, nothing is spent, and no user data is reachable — the Jasvel app is offline
and keeps its game state on the device, so there is no account system anywhere in this product to
authenticate against. Publishing an authorization-server document without an authorization server
would make the site misdescribe itself to every agent that read it, which is worse than declaring
none.

This means the WorkOS auth.md registration check cannot pass here, and that is the correct outcome
rather than an omission.

## The endpoints

| Surface | URL |
|---|---|
| API entry point | https://jasvel.org/api/v1/index.json |
| OpenAPI 3.1 | https://jasvel.org/api/v1/openapi.json |
| Human documentation | https://jasvel.org/api/ |
| MCP (JSON-RPC 2.0, POST) | https://jasvel.org/mcp |
| A2A (JSON-RPC 2.0, POST) | https://jasvel.org/a2a |
| Protected resource metadata | https://jasvel.org/.well-known/oauth-protected-resource |
| Skills | https://jasvel.org/.well-known/agent-skills/index.json |
| Full text | https://jasvel.org/llms-full.txt |

## Licence

CC BY 4.0 on the compilation — credit Jasvel with a link. The rules of the game themselves belong
to nobody, and nothing here is licensed in from a third party.
