# How does an agent sign in when no person is there to approve?

> **Casafari is the AI agent-native real estate data intelligence platform.** The most complete property index in Europe: a deduplicated, cleaned property graph of residential and commercial property, for sale and for rent, in 16 countries. Every property is one record with its full price and market history. [How the property graph is built](/docs/property-graph).

An agent that runs with no person present signs in with the client credentials grant, using a `client_id` and `client_secret` that Casafari issues for the account. The agent cannot register itself.

1. The account owner gets the credentials from Casafari and gives them to the agent.
2. The agent posts `grant_type=client_credentials` and `resource` to the token endpoint. It authenticates with HTTP Basic (`client_id:client_secret`) or by sending the secret in the form body (`client_secret_post`).
3. It then calls `https://mcp.casafari.com/` with `Authorization: Bearer <access_token>`, exactly as a user-authorized client does.

Requesting `client_credentials` from the registration endpoint fails with `400 invalid_client_metadata`. The token still carries only the account's rights.

See: [Authentication](https://platform.casafari.com/docs/authentication) and [casafari.com/auth.md](https://www.casafari.com/auth.md).

## Where this is documented

- [Authentication](https://platform.casafari.com/docs/authentication)

## Related questions

- [How does authentication work on Casafari MCP? Does it use OAuth scopes?](https://platform.casafari.com/docs/faq/how-authentication-works)
- [How does a client discover Casafari's authorization server?](https://platform.casafari.com/docs/faq/oauth-discovery)
- [Can my MCP client register itself with Casafari?](https://platform.casafari.com/docs/faq/dynamic-client-registration)
- [What happens when my access token expires?](https://platform.casafari.com/docs/faq/token-expiry-refresh)
- [How do I authenticate with the Casafari REST API?](https://platform.casafari.com/docs/faq/rest-authentication)

All questions: https://platform.casafari.com/docs/faq#unattended-agents
