generated: '2026-09-19' method: searched source: https://api.rosentic.com/.well-known/oauth-authorization-server docs: - https://rosentic.com/mcp/ - https://rosentic.com/docs/ - https://rosentic.com/docs/integrations/ - https://api.rosentic.com/onboard - https://pypi.org/project/rosentic-mcp/ summary: types: [oauth2, http-bearer, none] api_key_in: [header] oauth2_flows: [authorizationCode] bearer: true pkce: S256 dynamic_client_registration: true credential_classes: 4 headline: >- Four ways in, by surface. (1) Rosentic Remote MCP at https://api.rosentic.com/mcp: OAuth 2.1 authorization-code with PKCE S256 for a public client, dynamic client registration, one scope rosentic:remote:read — discovered through the RFC 9728 / RFC 8414 chain the endpoint's 401 points at — or a Rosentic API key as a Bearer token. (2) The REST feed and the dashboard-backed MCP tools: a workspace API key (ros_live_ prefix) as Authorization: Bearer, issued once at onboarding. (3) The A2A agent: anonymous for public repos (3 requests/hour per IP, 250MB repo cap) or Bearer API key for private repos and Merge Index. (4) The GitHub Action and the six offline MCP tools: no credential at all — "No signup. No API key. No account." No OIDC is served (/.well-known/openid-configuration 404), and no OpenAPI declares any of this, so derive-authentication.py had nothing to read. schemes: - name: RosenticRemoteOAuth type: oauth2 applies_to: [https://api.rosentic.com/mcp] flows: - flow: authorizationCode authorizationUrl: https://api.rosentic.com/oauth/authorize tokenUrl: https://api.rosentic.com/oauth/token scopes: {rosentic:remote:read: Read the hosted run_status / which_lane / get_verdict tools} pkce: S256 (required for the public client — token_endpoint_auth_methods_supported is [none]) grant_types: [authorization_code, refresh_token] registration_endpoint: https://api.rosentic.com/oauth/register discovery: authorization_server: well-known/rosentic-com-oauth-authorization-server.json protected_resource: well-known/rosentic-com-oauth-protected-resource.json challenge: 'HTTP 401 with WWW-Authenticate: Bearer resource_metadata="https://api.rosentic.com/.well-known/oauth-protected-resource/mcp", scope="rosentic:remote:read"' observed: - {url: 'https://api.rosentic.com/oauth/authorize', method: GET, http_status: 400, body: '{"error":"invalid_request","error_description":"response_type must be code"}'} - {url: 'https://api.rosentic.com/oauth/register', method: POST, body: '{}', http_status: 400, body_out: '{"error":"invalid_client_metadata","error_description":"redirect_uris must contain 1 to 10 HTTPS or loopback HTTP URIs without fragments"}'} sources: [well-known/rosentic-com-oauth-authorization-server.json, 'https://rosentic.com/llms.txt — "Hosted MCP endpoint: https://api.rosentic.com/mcp (OAuth 2.1, PKCE, dynamic client registration)"'] - name: RosenticApiKey type: http scheme: bearer bearerFormat: 'Rosentic workspace API key, prefix ros_live_' in: header parameter: 'Authorization: Bearer ' applies_to: ['https://api.rosentic.com/mcp (alternative to OAuth per the 401 body)', 'GET https://api.rosentic.com/v1/feed/rules', 'MCP local tools get_verdict and get_remediation_queue', 'GitHub Action input api-key / env ROSENTIC_API_KEY (turns on dashboard history)', 'A2A bearer scheme for private repos, higher limits, Merge Index'] issuance: where: https://api.rosentic.com/onboard how: 'Sign in with GitHub (read:org read:user user:email) or a magic-link email, select an org to create a workspace, install the GitHub App or "claim without installing"; "This secret was returned by the claim and is shown once."' cost: free (Free-with-key tier — 3 repos, 1,000 scans/month, 30-day history) sources: ['https://rosentic.com/docs/ — Enable dashboard history', 'https://rosentic.com/docs/integrations/ — curl https://api.rosentic.com/v1/feed/rules -H "Authorization: Bearer $ROSENTIC_API_KEY"', 'https://pypi.org/project/rosentic-mcp/ — get_verdict "Requires ROSENTIC_API_KEY (a ros_live_ workspace key)"', 'MCP 401 body next_step'] - name: Anonymous type: none applies_to: ['A2A skills on public repos — "Public repos, 3 requests/hour per IP, 250MB repo cap" (agent card authentication.schemes[0])', 'GitHub Action in anonymous mode (uses the runner''s GITHUB_TOKEN only)', 'The six offline MCP tools and rosentic-mcp gate', 'get_policy — "Public read - no key needed"'] sources: [a2a/rosentic-com-agent-card.json, 'https://github.com/Rosentic/rosentic-action README — "No signup. No API key. No account."'] - name: GitHubOAuthSignIn type: oauth2 audience: dashboard sign-in, not API auth applies_to: [https://api.rosentic.com/auth/github] observed: {http_status: 302, location: 'https://github.com/login/oauth/authorize?client_id=Ov23lipUElad6nbA4R9W&redirect_uri=https%3A%2F%2Fapi.rosentic.com%2Fauth%2Fgithub%2Fcallback&scope=read%3Aorg+read%3Auser+user%3Aemail&state=...'} note: Delegates identity to GitHub; "No write access requested" (onboard page). Email magic link is the alternative. Produces a dashboard session, which the MCP 401 body also accepts. gaps: - The A2A card carries its auth in the legacy authentication.schemes[] block rather than securitySchemes/security (see a2a/rosentic-com-a2a.yml deviations). - The OAuth metadata's resource_documentation and the 401 body's docs_url both point at github.com/Rosentic/rosentic/blob/main/docs/remote.md, which is not publicly readable (404); the readable remote docs are https://rosentic.com/mcp/. - GET https://api.rosentic.com/v1/feed/rules without a key returns the host's generic 404 ({"error":"not_found"}) rather than the documented 401 unauthorized, so an unauthenticated client cannot tell the endpoint exists.