# Set up Neotask for an agent Agent registration is available. Use this file as the entry point for Neotask account setup and API access. Re-read it at the start of a new setup because launch state and available operations can change. ## Start here 1. Read https://neotask.ai/auth.md and follow the current auth.md registration instructions exactly. Do not guess or reuse cached registration endpoints. 2. Request an access token for the resource `https://neotask.ai/api/agent`. 3. Send the token only in the `Authorization: Bearer ` header to `https://neotask.ai/api/agent/v1/*`. 4. Call `GET https://neotask.ai/api/agent/v1/me`, then `GET https://neotask.ai/api/agent/v1/capabilities`. ## Decide what you can do Treat `GET https://neotask.ai/api/agent/v1/capabilities` as the authority for this account. For each operation, check `scopeGranted`, `availability`, `reason`, and `idempotencyRequired` before acting. A documented endpoint is not permission to call it. - Use direct REST only for operations currently granted and available in the capability response. - Use remote MCP at https://neotask.ai/mcp only when its protected-resource metadata and the capability response both report it available. - Use the official Neotask CLI only after the API catalog at https://neotask.ai/.well-known/api-catalog publishes its package and verification metadata. https://neotask.ai/docs/cli.md explains installation, sign-in, the runner and every command family. - Find and install plugins and skills through Neotask Construct: https://neotask.ai/docs/construct.md covers search and install from the CLI and the Agent API. - If Neotask returns a claim, pairing, approval, integration, checkout, or desktop handoff, give the typed human-action URL to the user and wait for the resulting status change. - Free and paid access are determined by the effective capability response. Never infer access from marketing copy or from the existence of an endpoint. ## Safety rules - Never put access tokens, identity assertions, claim secrets, API keys, or integration credentials in URLs, chat messages, Markdown, logs, or tool output. - Never create or sign Neotask internal HMAC headers. Public agents authenticate with the issued bearer token; service-to-service HMAC remains internal. - Never approve a human-only action, open a checkout, connect an integration, or install software without the required human decision. - Use an idempotency key whenever the operation manifest requires one. Do not retry a non-idempotent action blindly. - Keep every account, Tenant, and handoff binding exactly as returned. Never merge, retarget, or substitute identities. ## Canonical references - API catalog: https://neotask.ai/.well-known/api-catalog - Authentication: https://neotask.ai/auth.md - Protected-resource metadata: https://neotask.ai/.well-known/oauth-protected-resource/api/agent - OpenAPI: https://neotask.ai/openapi.yaml - Agent documentation: https://neotask.ai/docs/llms.txt - Full agent documentation: https://neotask.ai/docs/llms-full.txt - Knowledge manifest: https://neotask.ai/agent-public-contracts/v1/knowledge-manifest.json - Scoped index: https://neotask.ai/agent-onboarding/llms.txt - Scoped index: https://neotask.ai/docs/api/llms.txt - Scoped index: https://neotask.ai/docs/cli/llms.txt - Scoped index: https://neotask.ai/docs/mcp/llms.txt - Scoped index: https://neotask.ai/docs/chat/llms.txt - Scoped index: https://neotask.ai/docs/automations/llms.txt - Scoped index: https://neotask.ai/docs/integrations/llms.txt - Scoped index: https://neotask.ai/docs/mail/llms.txt - Scoped index: https://neotask.ai/docs/runner/llms.txt - Scoped index: https://neotask.ai/docs/account/llms.txt - Scoped index: https://neotask.ai/docs/security/llms.txt - MCP instructions: https://neotask.ai/docs/mcp.md - CLI and local runner: https://neotask.ai/docs/cli.md - Construct plugins and skills: https://neotask.ai/docs/construct.md - Construct API OpenAPI: https://neotask.ai/api/construct/v1/openapi.json - Product documentation: https://neotask.ai/llms.txt (every page also has a Markdown copy at its address plus `.md`) - Every agent document: https://neotask.ai/sitemap-agent-docs.xml