# Mandatory Training auth.md

How AI agents and assistants can access https://getmandatorytraining.com, and what credentials exist for them.

## Who this is for

Agents and AI assistants that read the public course catalogue: which online courses we offer in a person's country, what each covers and costs, and what we say about whether an employer will accept the certificate.

## Access without credentials

Everything an agent can use here is public. None of it needs registration, an API key or a token:

- API catalog: https://getmandatorytraining.com/.well-known/api-catalog
- Read API description (OpenAPI): https://getmandatorytraining.com/agent/openapi.json
- Read API docs: https://getmandatorytraining.com/agent/docs
- MCP server (Streamable HTTP, POST): `https://getmandatorytraining.com/mcp`
- MCP server card: https://getmandatorytraining.com/.well-known/mcp/server-card.json
- Agent skill index: https://getmandatorytraining.com/.well-known/agent-skills/index.json
- Site overview for language models: https://getmandatorytraining.com/llms.txt

## Accounts and credentials

Agents can't register, sign in or hold accounts or credentials of their own here. There is no agent registration endpoint, so agents can't register accounts of their own. An assistant only ever holds a token a learner granted it, for that learner's account.

An agent can help someone find a course and send them to its page, where they enrol and study themselves.

## Connecting for a learner

An assistant can connect for one learner, with their consent, to read that learner's own account: their details, their courses and progress, and their certificates. Access is read-only. It can't take lessons or tests, get or pay for certificates, or change anything.

1. Register as a public client (OAuth dynamic client registration): POST https://getmandatorytraining.com/oauth/register with `client_name` and `redirect_uris` (https, or http on a loopback address). You get a `client_id` and no secret.
2. Send the learner to https://getmandatorytraining.com/oauth/authorize with `response_type=code`, your `client_id` and `redirect_uri`, a PKCE `code_challenge` with `code_challenge_method=S256`, `scope`, `state` and `resource=https://getmandatorytraining.com/mcp/account`.
3. The learner signs in with a 6-digit code we email them, typed into the same browser, sees what you're asking for, and chooses Allow or Deny.
4. Exchange the code at POST https://getmandatorytraining.com/oauth/token (`grant_type=authorization_code`, with the `code_verifier`).
5. Call the MCP server at `https://getmandatorytraining.com/mcp/account` (Streamable HTTP, POST) with `Authorization: Bearer <access token>`.

Scopes:

- `account.read`: See your name, email, country and your courses and progress.
- `certificates.read`: See and download your certificates.

Access tokens last 60 minutes. Refresh tokens rotate on every use, and using one twice ends the connection. A connection lasts 30 days from the learner's consent; then the learner allows it again.

The learner can disconnect an assistant at any time on their account page, which ends its tokens at once. An assistant can revoke its own tokens at POST https://getmandatorytraining.com/oauth/revoke. We can switch off an app that's misused.

Metadata:

- Authorization server: https://getmandatorytraining.com/.well-known/oauth-authorization-server
- Protected resource: https://getmandatorytraining.com/.well-known/oauth-protected-resource
