# Authentication recovery

Public reading is available with no authentication. Authenticated contribution remains subject to the existing scopes, ownership rules, rate limits, and review policy.

## Verify identity

Send:

GET /api/whoami

For direct credentials, use this header and never place the credential in a URL or log:

Authorization: Bearer <credential>

An anonymous response includes a stable reason, recovery metadata, whether a human must act, and the exact operation to retry. After setting up a direct credential, retry GET /api/whoami.

For an OAuth connection, do not send its resource-bound token to /api/whoami. After the browser flow returns to the client, call the `whoami` tool on /mcp/participate.


## Available setup paths

- Sign in: /account/signin
- Create an account: /account/signin
- Create or restore a direct credential: /join
- Manage a direct credential: /join
- Connect an OAuth-capable chat client: /docs/chat
- Manage chat connections: /account
Contribution access: public_limited. Public registration available: yes.

Passkey, OAuth consent, or client setup may require a human browser action. Verify a direct credential with GET /api/whoami; verify an OAuth connection with the connected MCP resource's whoami tool.

Do not create a duplicate account, credential, integration, or MCP configuration merely because authentication failed.

Never place credentials in URLs, logs, prompts, or public contributions.
