{"authorization_servers":["https://headlessdomains.com"],"bearer_methods_supported":["header"],"headlessdomains_authentication":{"auth_document":"https://headlessdomains.com/auth.md","capabilities":[{"description":"User API keys (hd_agent_ and hd_live_) identify a local account. They do not have independently selectable, enforced per-key permission scopes.","id":"user_api_keys","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"available"},{"description":"GFAVIP bearer credentials map an issuer-validated identity to a local account. The API's gfavip_token_required helper caches validation (60 seconds by default); other login/session paths have their own lifecycle, so this is not a service-wide revocation deadline. Signed identity-assertion exchange remains planned.","id":"gfavip_bearer","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"available"},{"description":"Protected operations apply their account, ownership, management and role checks. A valid credential or a published DNS, DID or Matrix record does not by itself authorize access to an unrelated domain.","id":"domain_authorization","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"available"},{"description":"Separately provisioned hd_org_ credentials are restricted by organization, active membership, endpoint allowlist, customer/domain binding and namespace-operation policy. These checks do not add per-key scopes to ordinary user API keys. See the reseller API for supported operations.","id":"reseller_organization_credentials","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"available"},{"description":"GET /api/v1/agents/me describes a user-key or GFAVIP identity without returning secrets or a credential-scope list. Anonymous and claimed states describe provisioning/account association, not independent verification of a person or service. hd_org_ credentials are not accepted by this endpoint.","id":"identity_introspection","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"available"},{"description":"A signed-in operator can bind an autonomous identity using its single-use claim code. This records account association; it does not certify a human's legal identity, agent safety or external marketplace admission.","id":"dashboard_claim","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"available"},{"description":"Public manifests, lookup responses, resolver records and SKILL files describe registration, anonymous provisioning, claimed accounts and stored operator links with the issuer, subject, record-read time, check and scope. None establishes independent human/service verification or external marketplace admission. Imported provider statements remain unverified here; human_backed is a deprecated alias for a stored operator link, not a human-verification result.","id":"public_identity_assurance","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"available"},{"description":"POST /oauth2/revoke revokes hd_agent_ and hd_live_ user keys immediately and idempotently. It does not revoke GFAVIP bearer tokens, browser sessions or hd_org_ credentials.","id":"user_api_key_revocation","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"available"},{"description":"MPP retries can use X-API-Key for actor identity alongside Authorization: Payment for a receipt. A payment receipt is not a general domain-management credential; check the specific paid endpoint's contract.","id":"payment_actor_separation","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"available"},{"description":"Ordinary user keys cannot be restricted to selectable read/write scopes. Legacy scopes_supported metadata lists service operations, not grants attached to a credential.","id":"user_api_key_scopes","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"not_implemented"},{"description":"Signed identity assertions, the associated OAuth token-exchange flow, and assertion-backed Delegated/Verified assurance are planned and unavailable here. Existing PowerLobster-to-GFAVIP login and account-management relationships are separate capabilities.","id":"signed_identity_assertion_exchange","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"planned"},{"description":"Provider identity-revocation events are not accepted by the user-key revocation endpoint; an events endpoint has not been implemented or advertised.","id":"provider_identity_revocation_events","owner":"HeadlessDomains.com repository maintainers","reviewed_on":"2026-09-27","status":"planned"}],"review_basis":"Repository implementation and local tests; external services require their own authentication and runtime checks.","schema_version":"1.0"},"resource":"https://headlessdomains.com","resource_name":"HeadlessDomains","scopes_supported":["domains:read","domains:write","agents:provision","profile:write","dns:write"]}
