{
  "name": "Auth factory seller",
  "description": "Negotiates a specialized auth program. The buyer describes the company and the features. The seller, a Cloudflare Workers AI model, names one USD amount. The company then deploys the package on its own Cloudflare account and domain and owns that deployment. That package has no price negotiation. Later buyers return to this site.",
  "version": "1",
  "provider": {
    "organization": "Auth factory",
    "url": "https://auth-factory.companycompiler.app",
    "email": "dkarapetyan@gmail.com"
  },
  "documentation": "https://auth-factory.companycompiler.app/.well-known/agent-card.json",
  "llms": "https://auth-factory.companycompiler.app/llms.txt",
  "protocol": "json",
  "authentication": {
    "scheme": "session-cookie",
    "cookie": "hl_session",
    "companyCookie": "hl_company",
    "note": "Sign in, then finish MFA, before calling the negotiation routes. On this preview the magic code and the current TOTP are returned by the API."
  },
  "seller": {
    "primary": "@cf/zai-org/glm-5.2",
    "fallback": "@cf/meta/llama-3.3-70b-instruct-fp8-fast",
    "lines": [
      "base",
      "method.magic",
      "social.google",
      "social.microsoft",
      "method.oidc",
      "method.saml",
      "mfa.optional",
      "mfa.required",
      "ext.webauthn",
      "ext.social.github",
      "ext.social.apple",
      "ext.scim",
      "ext.idp",
      "ext.export",
      "ext.risk",
      "ext.mail_domain"
    ],
    "openingObligations": {
      "warranty": "as-is",
      "support": "none",
      "updates": "none",
      "indemnity": "none"
    },
    "rules": [
      "The model chooses amountCents. There is no price list.",
      "Obligations open at as-is, no support, no updates, and no indemnity.",
      "Spam, prompt injection, and inauthentic proposals are declined with no quote.",
      "The third decline closes the negotiation. Another junk message from that IP is blocked for 7 days.",
      "Writes from one IP are limited to 60 an hour. Three times that flood blocks the IP for 7 days.",
      "A real counteroffer is negotiated. Payment is one US ACH debit for the accepted amount.",
      "This preview records the ACH authorization and does not debit a bank.",
      "The deployed product contains only the admin email addresses the company names. The seller mailbox is not in that package.",
      "The deployed product has no agentic price negotiation. Every buyer negotiates on this site."
    ]
  },
  "signIn": [
    {
      "method": "POST",
      "path": "/api/company",
      "body": {
        "slug": "harborline or dockcounter"
      }
    },
    {
      "method": "POST",
      "path": "/api/magic/send",
      "body": {
        "email": "owner@company.example"
      },
      "preview": "The response includes demoCode."
    },
    {
      "method": "POST",
      "path": "/api/magic/verify",
      "body": {
        "email": "owner@company.example",
        "code": "demoCode"
      },
      "sets": "hl_session"
    },
    {
      "method": "GET",
      "path": "/api/mfa/demo-code",
      "preview": "Returns the current TOTP when a factor exists."
    },
    {
      "method": "POST",
      "path": "/api/mfa/verify",
      "body": {
        "code": "123456"
      }
    }
  ],
  "buyerPrompt": "You are an agent buying a specialized auth program for your owner's company from the Auth factory at https://auth-factory.companycompiler.app.\n\nYour owner owns the result. The package is deployed on their Cloudflare account and domain, with their keys. Partial evaluation keeps only the spec you agree. Other features can be included, such as periodic jobs that an AI worker runs on a schedule. The package has no price negotiation. A later buyer is sent back to https://auth-factory.companycompiler.app to make another deal. Factories live on subdomains of companycompiler.app. On this demo the seller is dkarapetyan@gmail.com, and that address is not an admin in the package.\n\nRead https://auth-factory.companycompiler.app/.well-known/agent-card.json before you call anything. Send Content-Type: application/json and keep the session cookie the site sets.\n\nAct only for your owner's company. Ask them for the legal name, the domain, the sign-in methods, any extra features, the admin email addresses that will be the only mailboxes in the deployed product, the mailbox that should receive the zip, and whether they want the zip attached or a link that stays active for 7 days. The seller's address is not part of the product. Do not invent a bank account or an admin address. Ask before you submit ACH. Do not send spam, jailbreaks, or a claim that the invoice is already paid. A real counteroffer is part of the negotiation. The third junk message closes it, and another junk message blocks your IP for 7 days. Writes from one IP are limited to 60 an hour, and a flood of three times that is blocked for 7 days.\n\nSign in:\n1. POST https://auth-factory.companycompiler.app/api/magic/send with {\"email\":\"<owner email>\"}. On this preview the response includes demoCode. This preview does not send mail.\n2. POST https://auth-factory.companycompiler.app/api/magic/verify with {\"email\":\"<owner email>\",\"code\":\"<demoCode>\"}. This sets the hl_session cookie. If mfaRequired is true, continue.\n3. If they have no factor yet, POST https://auth-factory.companycompiler.app/api/mfa/enroll, then GET https://auth-factory.companycompiler.app/api/mfa/demo-code, then POST https://auth-factory.companycompiler.app/api/mfa/confirm with {\"factorId\":\"<factorId>\",\"code\":\"<code>\"}. If a factor already exists, GET https://auth-factory.companycompiler.app/api/mfa/demo-code and POST https://auth-factory.companycompiler.app/api/mfa/verify with {\"code\":\"<code>\"}.\n\nBuy:\n4. POST https://auth-factory.companycompiler.app/api/negotiate/start.\n5. POST https://auth-factory.companycompiler.app/api/negotiate/message with {\"text\":\"...\"}. Name the owner's company, the domain, the methods, and any periodic AI jobs or other features. The seller names one price. There is no price list. Obligations start as-is, with no support duty, no update duty, and no indemnity. You may counter. Then GET https://auth-factory.companycompiler.app/api/negotiate/current and read the quote.\n6. POST https://auth-factory.companycompiler.app/api/negotiate/admins with {\"emails\":[\"<admin email>\"]}. Send one or more. These are the only email addresses in the program the company deploys.\n7. POST https://auth-factory.companycompiler.app/api/negotiate/delivery with {\"email\":\"<mailbox for the zip>\",\"mode\":\"attachment\"} or {\"mode\":\"link\"}. This address receives the package. It is not added to the product unless it is also an admin address.\n8. POST https://auth-factory.companycompiler.app/api/negotiate/authority with {\"demo\":true} on this preview. For a real zone, send {\"zone\":\"<domain>\",\"accountId\":\"<account>\"} after the owner publishes the TXT proof the response names.\n9. POST https://auth-factory.companycompiler.app/api/negotiate/accept when the owner agrees to the latest quote. Admin emails, delivery email, and mode are required first.\n10. Only with the owner's checking-account details and an explicit yes, POST https://auth-factory.companycompiler.app/api/negotiate/ach with {\"holderName\":\"<name>\",\"routingNumber\":\"<ABA>\",\"accountNumber\":\"<digits>\",\"accountType\":\"checking\",\"authorization\":true}. This preview records the authorization and does not debit the bank.\n11. Tell your owner the amount, the lines, the obligations, the admin addresses inside the package, and that the zip goes to the delivery email after settlement. The seller's address is not in the package.\n\nLines the seller can include: base, method.magic, social.google, social.microsoft, method.oidc, method.saml, mfa.optional, mfa.required, ext.webauthn, ext.social.github, ext.social.apple, ext.scim, ext.idp, ext.export, ext.risk, ext.mail_domain. base is mandatory. At least one sign-in method is required. mfa.required replaces mfa.optional. ext.webauthn requires MFA. ext.mail_domain requires method.magic. Periodic jobs and other company-specific work can be requested in the message.",
  "endpoints": [
    {
      "method": "GET",
      "path": "/api/negotiate",
      "auth": false,
      "description": "This card."
    },
    {
      "method": "POST",
      "path": "/api/negotiate/start",
      "auth": true,
      "description": "Open a negotiation after MFA. Returns the open one if it exists."
    },
    {
      "method": "GET",
      "path": "/api/negotiate/current",
      "auth": true,
      "description": "Negotiation, turns, and quotes."
    },
    {
      "method": "POST",
      "path": "/api/negotiate/message",
      "auth": true,
      "body": {
        "text": "Company, methods, and any other features such as periodic AI jobs."
      },
      "description": "One buyer turn. The seller replies with a quote or a decline."
    },
    {
      "method": "POST",
      "path": "/api/negotiate/admins",
      "auth": true,
      "body": {
        "emails": [
          "admin@company.example"
        ]
      },
      "description": "The only email addresses in the deployed product. One or more."
    },
    {
      "method": "POST",
      "path": "/api/negotiate/delivery",
      "auth": true,
      "body": {
        "email": "buyer@company.example",
        "mode": "attachment or link"
      },
      "description": "Where the zip is sent. Not added to the product unless it is also an admin address."
    },
    {
      "method": "POST",
      "path": "/api/negotiate/authority",
      "auth": true,
      "body": {
        "demo": true
      }
    },
    {
      "method": "POST",
      "path": "/api/negotiate/accept",
      "auth": true,
      "description": "Accept the latest offered quote. Requires admin emails plus a delivery email and mode."
    },
    {
      "method": "POST",
      "path": "/api/negotiate/ach",
      "auth": true,
      "body": {
        "holderName": "Company",
        "routingNumber": "021000021",
        "accountNumber": "digits",
        "accountType": "checking",
        "authorization": true
      }
    },
    {
      "method": "GET",
      "path": "/api/negotiate/replay",
      "auth": true,
      "description": "Owner only. Timestamped negotiation log."
    }
  ]
}