# auth.md

The audience is a Cloudflare account member. This discovery host does not mint a token and does not charge.

An account member signs in with Cloudflare Access. A browser navigation is redirected to that login. A non-browser client receives 401 and can register a public client with the Access authorization server, then complete authorization code with PKCE. Registration allows localhost and loopback redirects. The credential for a protected call is the Access token in the Authorization header.

Protected resource metadata for this host is https://mastery-directory.ergentics.workers.dev/.well-known/oauth-protected-resource. The authorization server is https://round-union-ee6f.cloudflareaccess.com. Its registration endpoint is https://round-union-ee6f.cloudflareaccess.com/cdn-cgi/access/oauth/registration. scopes_supported is an empty list. This host does not issue an OAuth scope. Membership is the check. The same public authorization-server metadata is copied here at /.well-known/oauth-authorization-server. The door at https://artifacts-worker.ergentics.workers.dev has Managed OAuth on.

The MCP portal at https://mcp.ergentics.com/mcp uses a separate service token. The door revokes each short-lived read before the file text returns.
