# Confident AI auth.md

How AI agents and automated clients authenticate with Confident AI.

## Audience

Agents that call the Confident AI REST API (`api.confident-ai.com`,
EU: `eu.api.confident-ai.com`) or connect to the Confident AI MCP server
(`https://mcp.confident-ai.com/mcp`, EU: `https://eu.mcp.confident-ai.com/mcp`).

## REST API: API keys

The REST API authenticates with an API key sent as the `CONFIDENT_API_KEY`
request header. Keys are project-scoped and are created by a human in the
Confident AI dashboard at https://app.confident-ai.com. There is no
self-serve registration endpoint for API keys; an agent must be provisioned
a key by an account owner. Administrative operations (projects, members,
RBAC, governance) use an organization-scoped key with the Admin SDK — see
the `confident-client` skill in
https://www.confident-ai.com/.well-known/agent-skills/index.json.

- API reference: https://www.confident-ai.com/docs/reference/api
- OpenAPI spec: https://www.confident-ai.com/docs/openapi.yaml

## MCP server: OAuth 2.0

The MCP server uses OAuth 2.0 with PKCE and supports RFC 7591 dynamic
client registration, so an agent can register itself.

- Protected resource metadata (RFC 9728):
  https://mcp.confident-ai.com/.well-known/oauth-protected-resource
- Authorization server metadata (RFC 8414):
  https://api.confident-ai.com/.well-known/oauth-authorization-server/api/auth
- OpenID Connect discovery:
  https://api.confident-ai.com/api/auth/.well-known/openid-configuration
- Dynamic client registration (RFC 7591):
  https://api.confident-ai.com/api/auth/oauth2/register
- Grant types: `authorization_code`, `client_credentials`, `refresh_token`
- Tokens are sent as `Authorization: Bearer` headers.

The authorization flow requires a Confident AI user account; sign up at
https://app.confident-ai.com.

## Discovery on this origin

`/.well-known/openid-configuration`, `/.well-known/oauth-authorization-server`,
and `/.well-known/oauth-protected-resource` on this origin redirect to the
authoritative documents at the URLs listed in this file. Fetch those URLs
directly for spec-compliant issuer and resource validation.

- MCP setup guide: https://www.confident-ai.com/docs/reference/mcp
- Agent resources: https://www.confident-ai.com/.well-known/ai-catalog.json
