# auth.md: Karobar

How AI agents and automated clients get access to karobar.io, and what needs a person's account.

## Agent audience

Any AI agent, crawler or automated client that wants public facts about Karobar: plans and prices, features, platforms, guides, comparisons and contacts. Agents acting for a Karobar customer inside their account are not supported (see "Karobar accounts" below).

## Registration

No registration is needed. Access is anonymous: there is no agent sign-up, no registration endpoint and no API key to request. Start calling the endpoints below directly.

## Supported methods

- **Anonymous** (the only method). No credentials are issued or accepted. Requests are identified only by IP address (for rate limits) and by your `User-Agent` header, which we ask you to set to your agent's name and a contact URL.

## Endpoints

- **Pages as markdown.** Send `Accept: text/markdown` to any page URL, or add `/index.md` to it (for example `https://karobar.io/pricing/index.md`).
- **Site data API.** Read-only JSON about plans, features, platforms, guides and comparisons. Description: `https://karobar.io/openapi.json`. Catalog: `https://karobar.io/.well-known/api-catalog`.
- **MCP server** at `https://karobar.io/mcp` (Streamable HTTP, read-only tools). Card: `https://karobar.io/.well-known/mcp/server-card.json`.
- **A2A agent** at `https://karobar.io/a2a`, a rule-based guide that answers from the same site data. Card: `https://karobar.io/.well-known/agent-card.json`.
- **Summaries.** `https://karobar.io/llms.txt` and `https://karobar.io/llms-full.txt`.

## Credential use

There are no credentials to present: send requests without an `Authorization` header. The MCP and A2A endpoints are rate-limited per IP address and answer `429` when the limit is reached; static files (markdown, JSON) are not limited.

## Karobar accounts

Karobar accounts are for businesses and their teams, and are created by a person at `https://app.karobar.io` (email and password, Google, or Apple). A new account starts a free trial; no card is needed.

- Agents cannot register an account on someone's behalf.
- Karobar does not run an OAuth authorization server, so there is no OAuth discovery or protected-resource metadata, and no delegated access to a customer's inbox, orders or messages.
- To act inside a customer's Karobar account, the customer signs in and works in the app themselves.

## Contact

Questions about agent access: support@karobar.io, or `https://karobar.io/developers`.
