generated: '2026-09-19' method: searched source: https://api.sursatech.com/auth.md (saved verbatim at authentication/sursatech-com-auth.md), the agent card securitySchemes/security (a2a/sursatech-com-agent-card.json), the RFC 8414 / OIDC / RFC 9728 discovery documents in well-known/, and live anonymous probes of the endpoints on 2026-09-19. docs: https://api.sursatech.com/auth.md summary: types: - http http_schemes: - bearer oauth2_flows: - client_credentials (anonymous — token_endpoint_auth_methods_supported [none]) registration: anonymous dynamic self-registration (RFC 7591-style registration_endpoint, non-standard response shape) api_key_in: [] openapi: none — no OpenAPI is served (the api-catalog advertises https://api.sursatech.com/openapi.json, which 404s), so this profile is searched from the docs and discovery metadata rather than derived from a spec schemes: - name: bearerAuth type: http scheme: bearer bearerFormat: opaque description: Opaque bearer token returned by /api/a2a/register or /api/a2a/token, or minted out-of-band for known partners. header: 'Authorization: Bearer ' applies_to: every JSON-RPC method on POST https://api.sursatech.com/api/a2a (the card declares security [bearerAuth] at the card level with no per-skill override) sources: - a2a/sursatech-com-agent-card.json#securitySchemes.bearerAuth - https://api.sursatech.com/auth.md ("Credential Use") authorization_server: issuer: https://api.sursatech.com metadata: - https://api.sursatech.com/.well-known/oauth-authorization-server - https://api.sursatech.com/.well-known/openid-configuration - https://www.sursatech.com/.well-known/oauth-authorization-server (same content) registration_endpoint: https://api.sursatech.com/api/a2a/register token_endpoint: https://api.sursatech.com/api/a2a/token authorization_endpoint: https://api.sursatech.com/auth.md authorization_endpoint_note: The "authorization endpoint" is a markdown document, not an interactive grant UI — there is no user-facing authorization step; response_types_supported is ["none"]. jwks_uri: https://api.sursatech.com/.well-known/jwks.json jwks_note: '{"keys":[]} — empty; tokens are opaque, not JWTs, so there is nothing to verify offline and no token introspection endpoint is published.' grant_types_supported: - client_credentials token_endpoint_auth_methods_supported: - none scopes_supported: - a2a - company.read - requirements.write - booking.write agent_auth: note: A non-standard extension block in the RFC 8414 document describing agent registration. identity_types_supported: - anonymous credential_types_supported: - access_token - bearer register_uri: https://api.sursatech.com/api/a2a/register claim_uri: https://api.sursatech.com/api/a2a/register not_supported: ID-JAG identity assertions and user-claimed service-auth ceremonies (auth.md, "Registration") protected_resources: - resource: https://api.sursatech.com/api/a2a metadata: https://api.sursatech.com/.well-known/oauth-protected-resource bearer_methods_supported: [header] challenge: 'WWW-Authenticate: Bearer realm="SursaTech A2A", resource_metadata="https://api.sursatech.com/.well-known/oauth-protected-resource" (observed on an anonymous POST, HTTP 401 {"detail":"Missing bearer token"})' - resource: https://www.sursatech.com metadata: https://www.sursatech.com/.well-known/oauth-protected-resource note: the website origin declares itself a protected resource of the same authorization server; the API resource document on api.sursatech.com is the operative one for the A2A endpoint flows: - name: Anonymous self-registration documented_at: https://api.sursatech.com/auth.md steps: - 'POST https://api.sursatech.com/api/a2a/register with Content-Type: application/json and body {"name": "Your agent name"}' - 'Response (per auth.md): tokenType "Bearer" and accessToken; observed response fields on 2026-09-19: clientId (UUID), name, tokenType, accessToken, rateLimitPerMinute (60). An EMPTY body is accepted and a default name is assigned.' - The plaintext token is returned only once; store it securely. - 'Send Authorization: Bearer on POST https://api.sursatech.com/api/a2a' token_scope: self-registration tokens receive the A2A agent scope (a2a) and are rate-limited per client and per IP - name: Token endpoint documented_at: https://api.sursatech.com/.well-known/oauth-authorization-server (token_endpoint) and the card's x-sursatech-tokenUrl steps: - 'POST https://api.sursatech.com/api/a2a/token — observed on 2026-09-19 to answer an anonymous EMPTY JSON body with HTTP 200 {access_token, token_type "Bearer", scope "a2a", client_id} (RFC 6749 §5.1 field names, unlike /register)' note: auth.md does not document the token endpoint's request shape; the discovery metadata lists client_credentials with auth method none, and the empty-body probe confirms no client credential is required to mint an a2a-scoped token. - name: Partner credentials documented_at: a2a/sursatech-com-agent-card.json#securitySchemes.bearerAuth.description note: tokens "minted out-of-band for known partners" — no public flow; presumably the path to company.read / requirements.write / booking.write scopes beyond the default a2a scope revocation: self_service: false note: 'auth.md: "There is no self-service revocation endpoint yet. Contact info@sursatech.com to disable a registered agent credential."' contact: info@sursatech.com error_behaviour: missing_token: status: 401 body: '{"detail":"Missing bearer token"}' headers: www-authenticate: Bearer realm="SursaTech A2A", resource_metadata="https://api.sursatech.com/.well-known/oauth-protected-resource" note: The unauthenticated challenge fires before JSON-RPC method dispatch for the A2A 1.0 method names (SendMessage, GetTask); unknown method names return JSON-RPC -32601 with HTTP 200 without an auth check. provenance_note: 'This profile used no credential: it records the anonymous probes only. The tokens the empty-body probes returned were discarded and never sent to the API.'