Authentication · FAQ
How does an agent sign in when no person is there to approve?
An agent that runs with no person present signs in with the client credentials grant, using a client_id and client_secret that Casafari issues for the account. The agent cannot register itself.
- The account owner gets the credentials from Casafari and gives them to the agent.
- The agent posts
grant_type=client_credentialsandresourceto the token endpoint. It authenticates with HTTP Basic (client_id:client_secret) or by sending the secret in the form body (client_secret_post). - It then calls
https://mcp.casafari.com/withAuthorization: Bearer <access_token>, exactly as a user-authorized client does.
Requesting client_credentials from the registration endpoint fails with 400 invalid_client_metadata. The token still carries only the account's rights.
See: Authentication and casafari.com/auth.md.