# jobklick.it auth.md

## Audience and provisioning

Agents act on behalf of an existing jobklick.it user. The account owner signs in
at https://app.jobklick.it/login and creates a personal API token in https://app.jobklick.it/settings#extension.
The settings form submits POST /settings with `token` and a CSRF token in the
owner's authenticated browser session. There is no anonymous agent registration.
Account registration at https://app.jobklick.it/register is available only when sign-ups are open.

## Credentials

Send `Authorization: Bearer <personal-token>` to https://app.jobklick.it/api/jobs or https://app.jobklick.it/mcp.
`Authorization: Token <personal-token>` is also supported. Use HTTPS and keep the
token in secret storage. Never put credentials in discovery URLs or public files.
Tokens provide access to the owner's jobs and profile; there are no scoped tokens.
Renew the token in Settings to revoke the previous token immediately. Account
deletion also revokes access. A 401 response means a valid token is required.

This service uses Django personal tokens, not OAuth or OpenID Connect. It has no
OAuth issuer, authorization endpoint, token exchange, JWKS, or agent registration
API. An agent must ask the account owner to provision credentials.
