DocsCapabilitiesauth.md
auth.md
Telling an agent how to register for an account and get its own credentials, without a signup form or a consent screen.
Why an agent cares
Every other signal here assumes the agent is already allowed in. auth.md is the step before that, and its machine-readable half is an agent_auth block inside the OAuth metadata the MCP authorization signal already reads. An agent that finds a block advertising a registration method the service does not actually run has no way to get credentials, and no way to tell that from a service that never offered any.
Why we do not score it
Adoption
Early pilots. Named early adopters exist, behind flags or trials. Nothing has been independently measured yet.
Direction of travel: ▲ rising, as at .
Published by WorkOS on 2026-05-22 under MIT and at v0.6.0 by 2026-06-10, with Resend, here.now and Ora.ai listed as live services and Cloudflare, OpenAI, Anthropic, Cursor and Firecrawl named on the agent-provider side. No independent measurement of how many services publish an agent_auth block.
| Adopter | Depth | Evidence |
|---|---|---|
| Resend, here.now, Ora.ai (services) | production | auth-md.com |
| WorkOS (author) | production | workos.com |
Specifications
| Document | Revision | Kind |
|---|---|---|
| auth.md protocol specification | v0.6.0 | specification |
| RFC 9728 (OAuth Protected Resource Metadata, the discovery entry point) | living | specification |
Last re-read against the published documents: .