{
  "contractVersion": "v1",
  "schemaVersion": 1,
  "operationRegistryVersion": 3,
  "runtimeOperationRegistryVersion": 5,
  "sourceDigest": "8c57c4929bc859d307490158a857edaeaf7499fc94565a91196b3a771183c09c",
  "flows": [
    {
      "flowId": "identity_assertion",
      "owner": "identity_provider",
      "status": "feature-gated",
      "endpointRef": "/auth.md",
      "audience": "https://neotask.ai/api/agent",
      "requiredScopes": [
        "neotask:profile:read",
        "neotask:catalog:read"
      ],
      "requestSchemaRef": "AgentAuthFlowRequest.v1",
      "responseSchemaRef": "AgentAuthFlowResponse.v1",
      "challengeSchemaRef": "AgentAuthChallenge",
      "errorCodes": [
        "invalid_credential",
        "scope_denied",
        "claim_required"
      ],
      "notes": [
        "Use only a verified provider identity assertion.",
        "Site resolves the ordinary Tenant and AgentPrincipal from MongoDB."
      ]
    },
    {
      "flowId": "anonymous_agent_trial",
      "owner": "identity_provider",
      "status": "feature-gated",
      "endpointRef": "/auth.md",
      "audience": "https://neotask.ai/api/agent",
      "requiredScopes": [
        "neotask:profile:read",
        "neotask:catalog:read",
        "neotask:agents:read",
        "neotask:tasks:read"
      ],
      "requestSchemaRef": "AgentAuthFlowRequest.v1",
      "responseSchemaRef": "AgentAuthFlowResponse.v1",
      "challengeSchemaRef": "AgentAuthChallenge",
      "errorCodes": [
        "invalid_credential",
        "rate_limited",
        "claim_required"
      ],
      "notes": [
        "An admitted trial is authenticated and receives one ordinary Free Tenant, License, member, and AgentPrincipal.",
        "The trial is not human-verified and cannot use claim-gated integrations, Mail, billing, or pairing until claimed."
      ]
    },
    {
      "flowId": "service_auth_claim",
      "owner": "identity_provider",
      "status": "feature-gated",
      "endpointRef": "/auth.md#claim",
      "audience": "https://neotask.ai/api/agent",
      "requiredScopes": [
        "neotask:claim:read",
        "neotask:claim:write"
      ],
      "requestSchemaRef": "AgentAuthFlowRequest.v1",
      "responseSchemaRef": "AgentAuthClaimResponse.v1",
      "challengeSchemaRef": "AgentAuthChallenge",
      "errorCodes": [
        "claim_required",
        "claim_pending",
        "claim_expired",
        "claim_conflict"
      ],
      "notes": [
        "The service-auth caller has no product authority until the human completes the provider verification URI and code ceremony.",
        "Claim promotes existing records exactly once and never creates a second Tenant."
      ]
    },
    {
      "flowId": "token_exchange_rest",
      "owner": "identity_provider",
      "status": "feature-gated",
      "endpointRef": "/auth.md#rest",
      "audience": "https://neotask.ai/api/agent",
      "requiredScopes": [
        "neotask:catalog:read"
      ],
      "requestSchemaRef": "AgentAuthFlowRequest.v1",
      "responseSchemaRef": "AgentAuthFlowResponse.v1",
      "challengeSchemaRef": "AgentAuthChallenge",
      "errorCodes": [
        "invalid_credential",
        "audience_mismatch",
        "scope_denied"
      ],
      "notes": [
        "Tokens are short-lived bearer credentials for the exact REST audience.",
        "Neotask checks provider revocation and MongoDB principal state on each request."
      ]
    },
    {
      "flowId": "token_exchange_mcp",
      "owner": "identity_provider",
      "status": "feature-gated",
      "endpointRef": "/auth.md#mcp",
      "audience": "https://neotask.ai/mcp",
      "requiredScopes": [
        "neotask:catalog:read"
      ],
      "requestSchemaRef": "AgentAuthFlowRequest.v1",
      "responseSchemaRef": "AgentAuthFlowResponse.v1",
      "challengeSchemaRef": "AgentAuthChallenge",
      "errorCodes": [
        "invalid_credential",
        "audience_mismatch",
        "scope_denied"
      ],
      "notes": [
        "MCP uses a distinct audience and never forwards its token to a runner or Gateway.",
        "MCP tools are projected from the same effective registry."
      ]
    },
    {
      "flowId": "refresh",
      "owner": "identity_provider",
      "status": "feature-gated",
      "endpointRef": "/auth.md#refresh",
      "audience": null,
      "requiredScopes": [],
      "requestSchemaRef": "AgentAuthFlowRequest.v1",
      "responseSchemaRef": "AgentAuthFlowResponse.v1",
      "challengeSchemaRef": "AgentAuthChallenge",
      "errorCodes": [
        "invalid_refresh",
        "registration_revoked",
        "claim_required"
      ],
      "notes": [
        "Refresh remains provider-owned; Site never stores refresh material in the public contract or response."
      ]
    },
    {
      "flowId": "revoke",
      "owner": "identity_provider",
      "status": "feature-gated",
      "endpointRef": "/auth.md#revoke",
      "audience": null,
      "requiredScopes": [],
      "requestSchemaRef": "AgentAuthFlowRequest.v1",
      "responseSchemaRef": "AgentAuthRevokeResponse.v1",
      "challengeSchemaRef": "AgentAuthChallenge",
      "errorCodes": [
        "invalid_credential",
        "registration_revoked"
      ],
      "notes": [
        "Provider revocation and the Site registration revoke operation both deny future requests.",
        "Revocation is fail-closed across principal, tenant, runner, and integration state."
      ]
    }
  ]
}
