# auth.md — gsc-x402.ai (GreenCore Solutions Corp.)

## Posture

Everything on this surface is **open by design** — no authentication — with one exception: /api, the x402 door, whose terms are stated in its 402 payload only. Discovery endpoints (/.well-known/*) are public. x402 is declared as a capability (`x-gsc-x402: ready`) on every GSC door.

Anything that creates obligation — an RFQ, terms, a purchase order — leaves this surface through one of the two doors and is human-signed.

## Enforcement posture — the sign (declared 2026-08-24)

These endpoints are open by design. When the buy side's credential standard reaches GA — expected Q4 2026-Q1 2027 — transactional methods migrate to OAuth 2.1 challenge per the MCP 2025-11-25 specification. Read access stays open. That is not pending work; that is the published plan.

```json
{
  "enforcement_posture": "open-by-declaration",
  "migration_standard": "OAuth 2.1 + PKCE challenge (401 + WWW-Authenticate) on mcp:transact methods, per MCP spec 2025-11-25",
  "migration_trigger": "ecosystem GA of credentialed counterparties (enterprise A2A/MCP buy-side GA)",
  "migration_window": "Q4 2026 - Q1 2027",
  "declared": "2026-08-24",
  "operator": "GreenCore Solutions Corp.",
  "duns": "24-336-6774"
}
```

## Protected resource

- Resource: https://gsc-x402.ai
- Protected Resource Metadata: [/.well-known/oauth-protected-resource](/.well-known/oauth-protected-resource)
- Authorization server (Microsoft Entra): https://login.microsoftonline.com/54939635-2f2e-465a-8526-a907cb3c8ebd/v2.0
- AS metadata mirror: [/.well-known/oauth-authorization-server](/.well-known/oauth-authorization-server)
- Bearer tokens are presented in the Authorization header.

## Agent registration (self-contained flow)

- **Agent audience:** agents and the operators integrating them with GSC doors — AI Agents, the AI CPG Knowledge Graph, and this x402 door.
- **Registration endpoint:** https://gsc-navigator.ai/ — the GSC Trading Desk (the humans' channel, informed by Navigator). Intake on this surface (POST https://formspree.io/f/mnjozqpg with fields name, company, email, message) — human-reviewed by the GSC Trading Desk. There is no self-serve dynamic client registration; every registration is human-reviewed.
- **Agents' channel:** Instant Messaging — https://x-gsi.ai/ingest → https://mcp.cpghumanintheloop.ai/mcp (tools: submit_rfq, check_rfq_status, request_terms, escalate). Typed, identified, ticketed, human-signed.
- **Supported method — verified email:** GSC verifies the operator's email, then provisions credentials after review.
- **Credential use:** GSC issues **Microsoft Entra OAuth 2.0 client credentials** (client_credentials grant against the issuer above); present the access token as a **Bearer token in the Authorization header**. Revocation on request via the same endpoint.

```json
{
  "agent_auth": {
    "skill": "https://gsc-x402.ai/auth.md",
    "register_uri": "https://gsc-navigator.ai/",
    "identity_types_supported": [
      "identity_assertion"
    ],
    "identity_assertion": {
      "assertion_types_supported": [
        "verified_email"
      ],
      "credential_types_supported": [
        "oauth2_client_credentials"
      ]
    },
    "claim_uri": "https://gsc-navigator.ai/"
  }
}
```

Operator: GreenCore Solutions Corp. · D-U-N-S 24-336-6774 · Microsoft AI Cloud Partner.
