# auth.md — DLBR EID Gateway

This API provides tenant-scoped EUDI wallet verification through the DLBR
Gateway MCP endpoint at `https://api.dlbr.app/v1/mcp`.

## Audience and supported authentication

This document is for an AI agent or MCP client acting for a DLBR tenant. The
current authentication method is a tenant API key sent in the
`Authorization: Bearer <key>` HTTP header. Keys are tenant- and environment-
scoped and may be further limited by scopes.

There is currently no OAuth authorization server, OAuth token endpoint, agent
self-registration endpoint, ID-JAG exchange, identity claim ceremony, or
agent-token revocation endpoint for MCP access. Do not infer or fabricate
endpoints for these operations.

## Tenant administrator provisioning

Ask the tenant Owner or Admin to create a key in the [DLBR Dashboard API key
settings](https://console.dlbr.app/settings?tab=keys). The key should be
limited to the required scopes:

- `session:create` — start a wallet verification session.
- `session:read` — check a tenant-owned verification session.

The tenant administrator selects the environment and keeps the key in the MCP
client's secure credential store. Agents must not ask the user to place a key
in a chat, paste it into a prompt, or commit it to application source.

## MCP connection

- Endpoint: `https://api.dlbr.app/v1/mcp`
- Transport: Streamable HTTP
- Authentication: `Authorization: Bearer <tenant API key>`
- Server Card: `https://api.dlbr.app/.well-known/mcp/server-card.json`
- API reference: [Gateway MCP documentation](https://docs.dlbr.app/guide/mcp)

The endpoint exposes `list_supported_credential_types`,
`verify_credential`, and `check_verification`. The wallet presents credentials
directly to the Gateway. Results include a verdict and proven claim names;
claim values are not returned to the agent.

Supported credential profiles include EUDI PID (mDOC and SD-JWT VC) and EUDI
Proof of Age (mDOC). Tenant issuer policy may allow fewer credential and claim
combinations. An age predicate uses a separate Proof of Age credential; age is
not an EUDI PID attribute.

## Identity and revocation

EUDI wallet credentials are presented by the user to the Gateway as part of a
verification session. They are not agent-registration credentials. OAuth
identity types, credential issuance, and agent-token revocation URLs do not
apply because this service does not currently support agent OAuth
registration.
