# auth.md

Agent authentication and registration for BloomBridge (https://bloom-bridge.com).

## Audience

AI agents and assistants reading BloomBridge content, looking up a memorial, or
helping someone arrange flowers for a grave.

## Short version

**No registration. No sign-in. No token.** Every agent-facing service here is
anonymous and read-only. Ordering is the one thing an agent cannot do, by
design: it charges a card and dispatches a person to a specific grave, so a human
completes it in a browser.

## Registration

**There is no agent registration at BloomBridge, and none is required.**

There is no client registration endpoint, no developer signup, no API key
issuance and no approval step. Do not look for `/register`, `/oauth/register` or
a dynamic client registration document: they do not exist, and requesting them
returns 404.

An agent needs no identity here. Connect to the MCP server and call it.

If you need a formal relationship with us, write to support@bloom-bridge.com and
a person will answer.

## Sign-in

**There is no agent sign-in.** No OAuth flow is offered, no token endpoint
exists, and no bearer token is accepted or checked. Requests are anonymous and
unauthenticated.

Customer accounts at `/my-account/` are for people, in a browser, with a session
cookie. An agent must not attempt to authenticate as a customer, and must never
ask someone for those credentials.

## Services

| Service | Address | Auth |
| --- | --- | --- |
| MCP server | `https://bloom-bridge.com/mcp` | none |
| Server card | `/.well-known/mcp/server-card.json` | none |
| Skills index | `/.well-known/agent-skills/index.json` | none |
| API catalog | `/.well-known/api-catalog` | none |

The MCP server speaks JSON-RPC 2.0 over HTTP, protocol version 2025-06-18. POST
`initialize`, then `tools/list`, then `tools/call`. Five tools:

- `search_memorials` - find public memorial pages by name or cemetery
- `get_memorial` - full detail and delivery history for one memorial
- `list_arrangements` - the catalogue, with prices
- `list_plans` - one-time and recurring delivery plans
- `prepare_order` - builds a checkout link that arrives with the plan, arrangement
  and grave details already filled in, so the customer only confirms and pays
- `start_order` - returns a plain checkout URL for a person to open

Nothing writes. Nothing charges. Both order tools return a link and no more.

`prepare_order` is the useful one: gather what the person wants, call it, and hand
over the link. They land on a page showing exactly which arrangement is going to
which grave, and they pay. You cannot complete it for them, and no payment token
exists to try.

## Reading content without the MCP server

Everything public is also readable as plain documents, with no credentials.

| Surface | Address | Format |
| --- | --- | --- |
| Site overview | `/llms.txt` | text/plain |
| Any page as markdown | append `.md`, or send `Accept: text/markdown` | text/markdown |
| Memorial pages | `/memories/<slug>` and `/memories/<slug>.md` | text/html, text/markdown |
| Full URL inventory | `/sitemap.xml` | application/xml |

Markdown twins are rendered from the same records as the HTML, so the two cannot
drift apart.

## Memorial privacy

A memorial page is published only where the family chose to make it public.
Non-public memorials return 404 everywhere, including through the markdown twins
and every MCP tool. This is enforced per request, not by filtering a list.

Do not attempt to enumerate memorials by guessing slugs. `/sitemap.xml` lists
exactly the public ones.

## What not to crawl

`/findagrave/` is a separate blog holding integration scaffolding, not content,
and every page on it is `noindex`.

`/findagrave/api/` is disallowed in `robots.txt`. Each request carries a
single-use encrypted payload, so every link is unique and crawling produces tens
of thousands of dead URLs. The endpoint is open and unauthenticated; it is simply
not something to crawl.

## Ordering

Placing an order means taking a payment and sending a person to a grave. There is
no order API, no OAuth client-credentials flow and no token endpoint. Hand the
customer this link and let them finish:

    https://bloom-bridge.com/order-flow.html

## Content use

`robots.txt` carries:

    Content-Signal: search=yes, ai-input=yes, ai-train=yes

Search indexing, use as AI input, and use as training data are all permitted for
the public content described above.

## Contact

A person reads this address: support@bloom-bridge.com
