# auth.md — Yasmina API authentication

Yasmina is an embedded insurance platform. Its partner API is protected by
OAuth 2.0 using the client credentials grant. Credentials are issued to
organizations, not to individual end users and not to agents.

## Who this is for

This document is written for an autonomous agent that needs to call the
Yasmina partner API on behalf of an organization.

If you are that agent and you already hold a `client_id` and
`client_secret`, skip to [Obtaining a token](#obtaining-a-token). If you do
not hold credentials, read the next section before attempting anything:
there is no endpoint through which an agent can provision its own.

## Registration

Credentials are provisioned through the partner portal by a human
representative of the organization:

1. Create an account at https://portal.yasmina.ai/register
2. Complete onboarding with the organization's details.
3. Sandbox access is approved automatically. Production access requires
   commercial review and manual approval by Yasmina.
4. Once approved, retrieve the `client_id` and `client_secret` from the
   credentials section of the portal. The secret is shown only once at the
   time it is generated and can be regenerated from the same screen.

An agent cannot complete these steps. If you are an agent without
credentials, surface https://portal.yasmina.ai/register to the person you are acting for and
stop there. Do not attempt to register programmatically — no registration
endpoint is published, and probing for one will not find a different
answer than this document gives.

## Supported methods

| Method | Supported | Notes |
| --- | --- | --- |
| OAuth 2.0 client credentials (RFC 6749) | Yes | The only way to obtain an access token. |
| Dynamic client registration (RFC 7591) | No | No registration endpoint is published. |
| Identity assertion / ID-JAG | No | Assertions from an agent provider are not accepted. |
| Verified-email claim ceremony | No | There is no claim endpoint or user code flow. |
| Anonymous agent registration | No | Every token is bound to an approved organization. |

Yasmina publishes no `agent_auth` registration surface, because it
implements none of the flows one would describe. An agent gets exactly the
access its organization was granted, using that organization's credentials.

## Discovery

- Protected resource metadata (RFC 9728): https://yasmina.ai/.well-known/oauth-protected-resource
- Authorization server metadata (RFC 8414) is published by the
  authorization server itself, which is the partner API rather than this
  site: RFC 8414 requires the issuer value to be identical to the origin
  the document was retrieved from. Fetch it from the environment you are
  targeting:

  - https://sandbox.yasmina.ai/.well-known/oauth-authorization-server
  - https://production.yasmina.ai/.well-known/oauth-authorization-server

  Each environment serves its own protected resource metadata at
  `/.well-known/oauth-protected-resource` as well. Those copies are the
  authoritative ones; the copy on this site is a signpost to them.

## Environments

| Environment | Base URL | Notes |
| --- | --- | --- |
| Sandbox | https://sandbox.yasmina.ai | Sample data. No real policies are issued. |
| Production | https://production.yasmina.ai | Live processing and billing. |

## Obtaining a token

Exchange your credentials for an access token at the `/oauth/token` endpoint
of the environment you are targeting:

```http
POST https://production.yasmina.ai/oauth/token
Content-Type: application/json

{
  "grant_type": "client_credentials",
  "client_id": "your-client-id",
  "client_secret": "your-client-secret"
}
```

The response contains an `access_token` and `token_type` of `Bearer`.

## Calling the API

Send the token as a bearer credential on every request:

```http
Authorization: Bearer {access_token}
```

The header is the only accepted position for the token — it is not read
from a query parameter or a form body.

## Operational notes

- The `/oauth/token` endpoint is rate limited to 10 requests per minute.
  Cache the access token rather than requesting one per API call.
- Never expose `client_id` or `client_secret` in client-side code.
- Product access (motor, medical, property, travel, and others) is granted
  per client as a commercial entitlement. It is not requested through OAuth
  scope parameters, and sending a `scope` value does not widen access —
  which is why the protected resource metadata lists no supported scopes.

## Further reading

- Integration guides and endpoint reference: https://docs.yasmina.ai/introduction
- Machine-readable site overview: https://yasmina.ai/llms.txt
