agentic‑readiness docs
/
Build one › Run a scan ›

DocsCapabilitiesauth.md

auth.md

Telling an agent how to register for an account and get its own credentials, without a signup form or a consent screen.

adoption Early pilotstrend ▲ risingchecked on every pagestatus watchedverified 2026-08-26

Why an agent cares

Every other signal here assumes the agent is already allowed in. auth.md is the step before that, and its machine-readable half is an agent_auth block inside the OAuth metadata the MCP authorization signal already reads. An agent that finds a block advertising a registration method the service does not actually run has no way to get credentials, and no way to tell that from a service that never offered any.

Why we do not score it

One vendor's 0.x specification with no standards body, and it still renames things a client can see: v0.6.0 (2026-06-10) moved the email path out of identity_assertion into a new service_auth type and dropped verified_email from the assertion list. Score it once the specification reaches 1.0 or is submitted to a standards body, and agent_auth blocks appear beyond the authors' own ecosystem.

Adoption

Early pilots. Named early adopters exist, behind flags or trials. Nothing has been independently measured yet.

Direction of travel: ▲ rising, as at .

Published by WorkOS on 2026-05-22 under MIT and at v0.6.0 by 2026-06-10, with Resend, here.now and Ora.ai listed as live services and Cloudflare, OpenAI, Anthropic, Cursor and Firecrawl named on the agent-provider side. No independent measurement of how many services publish an agent_auth block.

AdopterDepthEvidence
Resend, here.now, Ora.ai (services)productionauth-md.com
WorkOS (author)productionworkos.com

Specifications

Last re-read against the published documents: .