# QTicket auth.md — Agent Registration and Authentication

> Agent registration metadata and authentication guide for the QTicket Platform (`qticket.net`).  
> Operator contact: <mailto:support@qticket.net>.  
> Public discovery endpoints are open and read-only. Passenger booking requires an authorized token.

---

## 1. Agent Registration

QTicket is Syria's multi-tenant bus ticketing platform. Public read-only endpoints (trip search, schedules, station directory, FAQ, and platform specifications) require no credentials and are accessible anonymously.

For autonomous AI agents intending to act on behalf of passengers or transport companies (such as creating bookings or querying private passenger records), authentication is required.

This document describes how an operator can register an agent identity, claim an existing identifier, and revoke credentials.

---

## 2. Identity & Operator

- **Platform:** QTicket (كيو تيكيت)
- **Domain:** `qticket.net` / `www.qticket.net`
- **Operator:** QTicket Engineering Team
- **Market:** Syrian Arab Republic
- **Currency:** Syrian Pound (SYP)
- **Support Contact:** <mailto:support@qticket.net>
- **Website:** https://www.qticket.net/

---

## 3. Supported Identity Types

### Anonymous (`anonymous`)
- **Access Level:** Full read-only access to trip schedules, stations, governorates, bus layouts, and FAQs.
- **Credential:** None required for public read-only requests. An optional `api_key` can be requested for higher rate limits.
- **Claim URI:** https://www.qticket.net/agent/auth/claim

### Identity Assertion (`identity_assertion`)
- **Assertion Types Supported:**
  - `urn:ietf:params:oauth:token-type:id-jag` (Identity-based JWT assertion)
  - `verified_email` (Domain/operator verified email address)
- **Credential Types Supported:**
  - `api_key`
  - `bearer_token` (JWT via OAuth 2.0 Authorization Server)
- **Claim URI:** https://www.qticket.net/agent/auth/claim
- **Revocation URI:** https://www.qticket.net/agent/auth/revoke
- **Events Supported:**
  - `urn:ietf:params:oauth:event:revocation`

---

## 4. Registration Workflow

### Step 1: Submit Registration
Operators can submit agent registration via email or POST to the registration pathway:
- **Endpoint:** `https://www.qticket.net/agent/auth/register`
- **Email:** <mailto:support@qticket.net?subject=Agent%20Registration>
- **Required Payload/Information:**
  1. `agent_name`: Name and version of the agent software (e.g. `MyTravelBot/1.0`).
  2. `operator_name`: Legal organization or individual operator.
  3. `contact_email`: Operator contact email.
  4. `purpose`: Brief statement of intended actions (e.g. "Trip discovery and passenger assistance").
  5. `identity_type`: `"anonymous"` or `"identity_assertion"`.
  6. `assertion_type`: Optional assertion type if using ID-JAG or verified email.

A confirmation response is returned with the assigned agent identifier and operational rate limits.

---

## 5. Identifier Claim

To claim an existing agent identifier or update credentials:
- **Endpoint:** `https://www.qticket.net/agent/auth/claim`
- **Email:** <mailto:support@qticket.net?subject=Agent%20Claim>
- Include proof of control (signed message or verified domain contact).

---

## 6. Revocation & Lifecycle Management

To revoke an issued credential or deregister an agent:
- **Endpoint:** `https://www.qticket.net/agent/auth/revoke`
- **Email:** <mailto:support@qticket.net?subject=Agent%20Revocation>
- Revocation events are processed immediately upon receipt.

---

## 7. Operational Standards & Rate Limits

- **Passive discovery:** Public discovery documents (`/.well-known/*`, `/llms.txt`, `/openapi.json`) are cached and globally accessible.
- **Rate limits:** Up to 120 requests per minute for registered agents.
- **Language:** All responses support Arabic (default) and English.

---

## 8. Related Discovery Documents

- **API Catalog (RFC 9727):** [/.well-known/api-catalog](https://www.qticket.net/.well-known/api-catalog)
- **OAuth Authorization Server:** [/.well-known/oauth-authorization-server](https://www.qticket.net/.well-known/oauth-authorization-server)
- **OAuth Protected Resource:** [/.well-known/oauth-protected-resource](https://www.qticket.net/.well-known/oauth-protected-resource)
- **MCP Server Card:** [/.well-known/mcp/server-card.json](https://www.qticket.net/.well-known/mcp/server-card.json)
- **Agent Skills Index:** [/.well-known/agent-skills/index.json](https://www.qticket.net/.well-known/agent-skills/index.json)
- **OpenAPI 3.1 Spec:** [/openapi.json](https://www.qticket.net/openapi.json)
- **LLM Summary:** [/llms.txt](https://www.qticket.net/llms.txt)
