feat(agents): fix ARD manifest, publish auth.md and OAuth AS metadata - #1716
Merged
Merged
Conversation
Three is-agentic.com / isitagentready.com discoverability checks: - ARD (ai-catalog.json): the manifest was missing displayName on its one entry and had no host object or representativeQueries, all required by the spec. Content-Type was also application/ai-catalog+json instead of the spec's application/json. Fixed the existing MCP entry and added a second real entry for this site's own /openapi.json. - auth.md: didn't exist. Added at /auth.md, referencing the existing oauth-protected-resource metadata rather than duplicating it. - OAuth Authorization Server metadata: astro.config.mjs/server.mjs already had a content-type mapping for /.well-known/oauth-authorization-server, but no file ever backed it. Added one (RFC 8414 shape, mirroring the real fields already published in openid-configuration) plus the agent_auth extension block auth.md's spec asks for, and bearer_methods_supported on oauth-protected-resource. Note on agent_auth: the skill's three named identity flows (ID-JAG, verified-email, anonymous) don't match how Datum's IAM actually works today (OAuth service accounts via client_credentials / jwt-bearer). Rather than force-fit one of those flows, the block describes the real mechanism under identity_types_supported: ["service_account"] with real endpoints (register_uri is the actual signup URL, revocation_uri is the actual revocation_endpoint). This may not fully satisfy the scanner's flow-shape check, but it doesn't misrepresent what Datum's auth actually does — same principle already established in src/data/openapi.ts and src/data/mcpServerCard.ts. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Contributor
🔎 SEO & Meta ReviewSkipped (mode: Changed files do not include any |
AriaEdo
approved these changes
Sep 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Addresses two of the three isitagentready.com findings passed along; DNS-AID (the third) is tracked separately as blocked (#1715).
ARD manifest —
entry 0 is missing displayName/.well-known/ai-catalog.jsonwas missingdisplayNameon its one entry, and had no top-levelhostobject orrepresentativeQueries— all required by the ARD spec.Content-Typewas alsoapplication/ai-catalog+jsoninstead of the spec's plainapplication/json.Fixed the existing MCP entry and added a second, real entry for this site's own
/openapi.json.auth.md —
not foundDidn't exist. Added
/auth.md, referencing the existing/.well-known/oauth-protected-resourcemetadata rather than duplicating it, per the spec's "when OAuth metadata is available, reference it" guidance.OAuth Authorization Server metadata
astro.config.mjs/server.mjsalready had a content-type mapping registered for/.well-known/oauth-authorization-server— but no file ever backed it, so it 404'd. Added one (RFC 8414 shape, mirroring the real fields already published inopenid-configuration), plus:agent_authextension block on it, per the auth.md specbearer_methods_supported: ["header"]onoauth-protected-resource(spec requires it)ai-catalog.json,auth.md) inserver.mjsA judgment call worth flagging:
agent_auth's identity flowThe auth.md skill's spec names three identity flows for the
agent_authblock — ID-JAG, verified-email, anonymous — each with specific required sub-fields. None of them match how Datum's IAM actually works today: real OAuth service accounts viaclient_credentials/urn:ietf:params:oauth:grant-type:jwt-bearer(confirmed live inopenid-configuration'sgrant_types_supported), not token-exchange federation, not an email-linked agent identity, and definitely not anonymous access.Rather than force-fit the data into one of those three shapes to make the scanner's flow-check happy,
agent_authhere describes the real mechanism underidentity_types_supported: ["service_account"], with real endpoints —register_uriis the actual signup URL (https://auth.datum.net/id/signup),revocation_uriis the realrevocation_endpoint. This may not get a full green check on that specific sub-check, but it doesn't misrepresent what Datum's auth does — same "don't overclaim" principle already established insrc/data/openapi.tsandsrc/data/mcpServerCard.ts.Test plan
npx astro check— 0 errorsnpm run build— succeeds;oauth-authorization-servercopies todist/client/.well-known/correctlypython3 -m json.tool)POST https://isitagentready.com/api/scan {"url": "https://www.datum.net"}post-deploy — confirmchecks.discovery.ard.statusandchecks.discoverability.authMd.status🤖 Generated with Claude Code