# M4G1C M4NT4 — authentication for agents

M4G1C M4NT4 has one authenticated machine surface: the MCP server at https://magicmanta.com/mcp. There is no API key system and no public REST API. Agents act on behalf of a signed-in human user; every request runs with that user's permissions and limits.

## Discover

- Protected resource metadata (RFC 9728): https://magicmanta.com/.well-known/oauth-protected-resource
- An unauthenticated request to https://magicmanta.com/mcp returns HTTP 401 with `WWW-Authenticate: Bearer resource_metadata="https://magicmanta.com/.well-known/oauth-protected-resource"`.
- The authorization server is our managed auth provider, listed in `authorization_servers` of that document. Its RFC 8414 metadata: https://cylatnxyocxtmmnejajy.supabase.co/auth/v1/.well-known/oauth-authorization-server

## Pick a method

- agent_auth: not applicable. We do not run an identity_endpoint, and do not accept identity_assertion, service_auth or id-jag tokens.
- Supported: OAuth 2.0 authorization code flow with PKCE, started by your MCP client from the metadata above.

## Register

Not applicable — no agent registration endpoint. Use the client registration your MCP client performs with the authorization server above.

## Claim

Not applicable — no claim endpoint. The human user signs in at https://magicmanta.com/auth with Google, Apple, Microsoft, AgentID, or email and password, completes two-factor sign-in with an authenticator app (required for every account), and approves access on the consent screen.

## Exchange

Not applicable — no custom exchange endpoint. Exchange the authorization code at the token endpoint given in the authorization server metadata.

## Use the access_token

Send `Authorization: Bearer <access_token>` on every request to https://magicmanta.com/mcp. Tools: lookup_socials, list_my_lookups, list_my_lists. MCP lookups are capped at 100 per account per day.

## Errors

- 401 `{"error":"unauthorized"}` with a WWW-Authenticate header: missing or invalid token.
- Tool errors are returned as MCP tool errors with a plain-language message (for example, the daily limit).

## Revocation

The user can sign out or delete their account at https://magicmanta.com/account. Questions: support-magicmanta@agentmail.to
