# auth.md

Machine-readable authentication guide for AI agents calling the Intlayer API.

## Audience

Autonomous agents and scripted clients that need to read or write Intlayer
dictionaries, projects and translations programmatically.

## Resource

- **API base URL:** https://back.intlayer.org
- **Protected resource metadata:** https://intlayer.org/.well-known/oauth-protected-resource
- **Authorization server metadata:** https://back.intlayer.org/.well-known/oauth-authorization-server

## Registration

Intlayer does **not** support dynamic client registration. Credentials are
issued per project by a human account holder:

1. Sign in at https://app.intlayer.org/projects.
2. Select or create a project.
3. Create an access key. The dashboard returns a **client ID** and a
   **client secret**; the secret is shown once.

An agent operating on a user's behalf must be handed these values out of band —
it cannot mint them itself.

## Obtaining a token

Exchange the access key for a bearer token using the OAuth 2.0
`client_credentials` grant. It is the only grant this API supports.

```http
POST https://back.intlayer.org/oauth2/token
Content-Type: application/json

{
  "grant_type": "client_credentials",
  "client_id": "<client id>",
  "client_secret": "<client secret>"
}
```

The token is valid for 7 days. Actively used tokens are extended
automatically; a client may also refresh one explicitly via
`POST https://back.intlayer.org/oauth2/token/extend`.

> **Note:** the token response is wrapped in Intlayer's standard envelope
> (`{ "data": { ... } }`) rather than returned as a bare RFC 6749 token
> response. Read the token from `data.accessToken`.

## Using the token

Send the token as a bearer credential on every request:

```http
GET https://back.intlayer.org/api/dictionary
Authorization: Bearer <access token>
```

## Authorization

Access is governed by the role attached to the access key, not by requested
OAuth scopes. A key may additionally be restricted to specific environments and
locales. Requests outside those bounds fail with a permission error.

## Revocation

Delete the access key from the project dashboard at https://app.intlayer.org/projects.
Tokens issued from a deleted key stop validating.

## Documentation

https://intlayer.org/doc/concept/cms
