# Agentplace auth.md

Agentplace (https://agentplace.crossup.ai), by CrossUp, needs **no authentication and no registration** for any of its agent surfaces. There are no accounts, API keys, OAuth flows or scopes to request: an agent can call everything below anonymously, right away.

## Audience

Any AI agent, assistant, crawler or developer that wants to search the products of the 14 stores on Agentplace, read their Storegraph and send a shopper to buy on the merchant's store.

## Surfaces and how to call them

| Surface | URL | Auth |
|---|---|---|
| REST API (read-only) | https://agentplace.crossup.ai/api/v1 — OpenAPI: https://agentplace.crossup.ai/openapi.json | none |
| MCP server (Streamable HTTP) | https://agentplace.crossup.ai/mcp — card: https://agentplace.crossup.ai/.well-known/mcp/server-card.json | none |
| A2A agent (JSON-RPC) | https://agentplace.crossup.ai/a2a — card: https://agentplace.crossup.ai/.well-known/agent-card.json | none |
| Storegraph | https://agentplace.crossup.ai/.well-known/storegraph | none |
| Pages and Markdown twins | https://agentplace.crossup.ai (append `.md`) | none |

## Supported methods

- `anonymous`: the only method. Call any surface without credentials; nothing to claim, exchange or refresh.

## Registration

None. There is no registration endpoint and no credential to obtain, rotate or revoke. Send a descriptive `User-Agent` (name and contact URL) so we can reach you if something goes wrong.

## Credentials

Do not send credentials. An `Authorization` header is ignored. Agentplace never asks for, stores or forwards shopper credentials or payment data: the purchase happens on each merchant's own store.

## Limits

120 requests per 60 seconds per client IP on the product endpoints, MCP and A2A (`RateLimit` / `RateLimit-Policy` headers, `429` with `Retry-After` when exceeded). Every surface is read-only: nothing creates carts, orders or payments.

## Contact

hola@crossup.ai · docs: https://agentplace.crossup.ai/developers · terms: https://agentplace.crossup.ai/terminos
