generated: '2026-09-19' method: searched source: https://meetanlora.com/.well-known/agent-card.json docs: https://github.com/Stanglovicc/anlora-mcp spec: null summary: types: - none transport: n/a - the public agent surfaces require no credential; the web application uses a browser session note: >- No OpenAPI exists, so derive-authentication.py has nothing to read. The profile was assembled from the agent card (authentication.schemes ["none"], security [{scheme: none}]), the MCP manifest and repository README (stdio server, no environment variables, no keys - "Read-only. No customer data. No PII."), and the observed behaviour of the private application API under /api/. schemes: - name: anonymous type: none applies_to: - https://meetanlora.com/.well-known/agent-card.json (A2A agent card - four public-data skills) - npx -y github:Stanglovicc/anlora-mcp (MCP stdio server - four read-only tools) - https://meetanlora.com/.well-known/skills/index.json and the three SKILL.md files description: >- The card states "Read-only public benchmarks. No authentication required. No PII or operator-private data exposed via this agent." The MCP server runs locally with no configuration and calls no authenticated upstream. sources: - https://meetanlora.com/.well-known/agent-card.json - https://meetanlora.com/.well-known/mcp.json - https://raw.githubusercontent.com/Stanglovicc/anlora-mcp/main/README.md - name: application-session type: session applies_to: - https://meetanlora.com/api/* (private application API - not a public product) description: >- The customer dashboard (Laravel + Inertia) has an internal API under /api/ that robots.txt disallows and that answers anonymous requests with HTTP 401 {"error":{"code":"UNAUTHENTICATED","message":"Unauthenticated."}} (observed on GET /api/docs). The Privacy Policy names the session cookie anlora_session, a CSRF token, and passkeys (robots.txt Disallow /passkeys). Sign-in is at /login and /register (both 200). No API keys, tokens or OAuth clients are offered to customers or third parties anywhere in the public docs, pricing or terms - the product is sold as "no technical integration". sources: - https://meetanlora.com/api/docs - https://meetanlora.com/robots.txt - https://meetanlora.com/privacy identity: did: did:web:meetanlora.com did_document: https://meetanlora.com/.well-known/did.json jwks: https://meetanlora.com/.well-known/http-message-signatures-directory note: >- Cryptographic identity is published for the PROVIDER (to verify claims it signs and requests it emits), not as a credential a caller must present. It does not gate any surface. oauth: null