# EcoCheck auth.md

How AI agents authenticate with ecocheck.ai.

## Audience
AI agents and assistants (Claude, ChatGPT, MCP clients) acting for an EcoCheck
customer who wants the agent to read their own greenhouse-gas inventory data.

## Two levels of access
1. **Public, no credentials** — services, 2026 regulations, articles, the
   obligation checker: MCP https://ecocheck.ai/mcp, A2A https://ecocheck.ai/a2a, JSON https://ecocheck.ai/agent-api.
2. **The customer's own data, read-only** — MCP server https://ecocheck.ai/mcp/account
   protected by OAuth 2.1 (this document).

## Registration
Agents register as OAuth clients; they never create EcoCheck accounts.
- Dynamic client registration (RFC 7591): `POST https://ecocheck.ai/oauth/register`
  with `{"redirect_uris": [...], "client_name": "..."}`. Allowed redirect
  URIs: https://claude.ai/api/mcp/auth_callback, https://chatgpt.com/connector_platform_oauth_redirect, http://localhost:6274/oauth/callback. The response returns the public client_id
  (token_endpoint_auth_method `none`).
- Customer accounts are created by people at https://ecocheck.ai/auth/sign-up and activated
  by the EcoCheck team; an agent must never sign up or sign in on its own.

## Supported methods
- **oauth2-authorization-code + PKCE (S256)**, user-claimed: the customer signs
  in on the EcoCheck (AWS Cognito) login page and consents to scope
  `ecocheck/read`.
  - Protected resource metadata: https://ecocheck.ai/.well-known/oauth-protected-resource
  - Authorization server metadata: https://ecocheck.ai/.well-known/oauth-authorization-server
  - Authorization endpoint: https://ecocheck-agents.auth.ap-southeast-1.amazoncognito.com/oauth2/authorize
  - Token endpoint: https://ecocheck-agents.auth.ap-southeast-1.amazoncognito.com/oauth2/token
- **anonymous** for the public surfaces listed above.

## Credentials
- Access tokens are JWTs issued by https://cognito-idp.ap-southeast-1.amazonaws.com/ap-southeast-1_LPpQVcG9m, valid 60 minutes; refresh
  tokens 7 days; revocation at https://ecocheck-agents.auth.ap-southeast-1.amazoncognito.com/oauth2/revoke.
- Send `Authorization: Bearer <access_token>` to https://ecocheck.ai/mcp/account.
- Scope `ecocheck/read` is read-only: workspaces, organizations,
  facilities, inventories, reporting years and emission reports of the signed-in
  customer only. No writes, no member lists, no file exports. Requests are
  rate-limited per user and audit-logged.

## Acting for a user
Only read what the user asked for, keep their data confidential, and send them
to https://ecocheck.ai/contact for changes, demos or new inventories.
