# auth.md — Toonimo (www.toonimo.com)

Public marketing host: read-only agent discovery (MCP, markdown, llms.txt) and anonymous `POST /api/leads`. Tenant OAuth and authoring MCP live on **app.toonimo.com**.

## Agent registration

Registration methods supported:

- `anonymous`: read marketing content, call read-only MCP tools, and submit leads via [openapi.json](https://www.toonimo.com/openapi.json). No account, registration, or credential is created on www; call the endpoints directly.
- `tenant_oauth` (provisioning): authors and integrators sign in at [app.toonimo.com](https://app.toonimo.com) for dashboard access and authenticated `GET/POST …/api/v2/mcp/*` (JWT + `domain_id`). Not hosted on www.

There is no `POST /agent/auth` registration endpoint on www.

Machine-readable summary (Auth.md `agent_auth` metadata):

```json
{
  "agent_auth": {
    "skill": "https://www.toonimo.com/auth.md",
    "identity_types_supported": ["anonymous"],
    "anonymous": {
      "credential_types_supported": ["none"],
      "claim_uri": "https://www.toonimo.com/openapi.json"
    },
    "register_uri": null,
    "provisioning": {
      "tenant_portal": "https://app.toonimo.com"
    }
  }
}
```

Discovery:

- Protected resource: [/.well-known/oauth-protected-resource/en](https://www.toonimo.com/.well-known/oauth-protected-resource/en)
- Authorization server: [/.well-known/oauth-authorization-server](https://www.toonimo.com/.well-known/oauth-authorization-server)

## Host roles

| Host | Role |
|------|------|
| `www.toonimo.com` | This document — public agents & crawlers |
| `app.toonimo.com` | Customer app portal — OAuth, tenant MCP |

## Human access

- [Request a demo](https://www.toonimo.com/en/demo) · [Contact](https://www.toonimo.com/en/contact)
- Security: info@toonimo.com

## Machine-readable indexes

- [llms.txt](https://www.toonimo.com/llms.txt)
- [AI catalog](https://www.toonimo.com/.well-known/ai-catalog.json)
- [For agents](https://www.toonimo.com/en/for-agents)
