# auth.md - Seam Agent Registration

## Overview

This document specifies authentication and registration procedures for autonomous AI agents connecting to Seam.

## Identification

- **Service**: Seam
- **Domain**: https://getseam.app
- **Authorization Server**: https://getseam.app/.well-known/oauth-authorization-server
- **Protected Resource**: https://getseam.app/.well-known/oauth-protected-resource

## Supported Identity Types

Seam supports two identity assertion methods for autonomous agents:

1. **Verified Email (`verified_email`)**:
   - Verification via OAuth authorization code flow.
   - UserInfo endpoint: `https://getseam.app/api/auth/oauth2/userinfo`
2. **Identity Assertion (`identity_assertion`)**:
   - Cryptographic identity assertions via RFC 9421 HTTP Message Signatures and ID-JAG token specification (`urn:ietf:params:oauth:token-type:id-jag`).

## Registration

- **Registration Endpoint**: `https://getseam.app/api/auth/oauth2/register`
- **Method**: POST
- **Payload**: JSON with `client_name`, `redirect_uris`, `grant_types`, and `contacts`.

## Token Exchange & Credentials

- **Token Endpoint**: `https://getseam.app/api/auth/oauth2/token`
- **Bearer Method**: `Authorization: Bearer <token>` HTTP header on all API requests.
- **JWKS Endpoint**: `https://getseam.app/api/auth/oauth2/jwks`
