# auth.md

marcopontili.com is a public portfolio site. Everything an agent can read is
public, and there is nothing to sign in to.

## Authentication

None. There are no user accounts, no API keys, no tokens, and no agent
registration endpoint. Every URL listed in
[llms.txt](https://marcopontili.com/llms.txt) and
[sitemap.xml](https://marcopontili.com/sitemap.xml) is served anonymously over
HTTPS.

There is deliberately **no OAuth**: no `/.well-known/oauth-authorization-server`,
no `/.well-known/oauth-protected-resource`, and no protected resource to
authorize against. A scanner looking for those will find nothing, and that is
the correct result rather than a misconfiguration.

## How to read this site

- Fetch any page with `Accept: text/markdown` to get a markdown rendering, or
  append `.md` to the path (`/about` → `/about.md`).
- [llms.txt](https://marcopontili.com/llms.txt) is the hand-maintained index of
  pages, case studies, and policies.
- [/.well-known/api-catalog](https://marcopontili.com/.well-known/api-catalog)
  (RFC 9727) links to the OpenAPI description and the status document.
- [robots.txt](https://marcopontili.com/robots.txt) carries the crawl rules and
  a `Content-Signal` directive: `ai-train=no, search=yes, ai-input=yes`.

## Rate limits

No published quota. Keep request rates polite; `robots.txt` asks for
`Crawl-delay: 2`.

## Contact

A human reaches the site owner through
[/contact](https://marcopontili.com/contact). Agents acting for a user should
surface that page rather than attempting to submit the form.
