# call4me auth.md

How an AI agent gets credentials for call4me. Every call4me operation acts for a call4me user: placing calls, reading calls and the calling profile, and spending or adding credits. Reading the site and its discovery documents needs nothing.

## Who signs in

Agents act on behalf of a call4me user. There are no agent-only accounts and no separate sign-up: the user signs in through the browser (Google or X), which creates their account the first time, and approves the agent once. Tokens are then bound to that user and spend that user's credits.

## Registration

- Authorization server: https://call4.me/api/auth (metadata at https://call4.me/.well-known/oauth-authorization-server)
- Dynamic client registration (RFC 7591), no credentials needed: POST https://call4.me/api/auth/oauth2/register with client_name, redirect_uris, grant_types ["authorization_code","refresh_token"], response_types ["code"], token_endpoint_auth_method "none", and application_type "native" when the redirect URI is a loopback address.
- Protected resources: https://call4.me/mcp (the MCP server) and https://call4.me/ (GET /api, credits over x402); metadata at https://call4.me/.well-known/oauth-protected-resource/mcp and https://call4.me/.well-known/oauth-protected-resource. Ask for the one you need with the RFC 8707 resource parameter; the scope is `calls`.

## Getting a token

1. Send the user to https://call4.me/api/auth/oauth2/authorize with response_type=code, your client_id, redirect_uri, scope (calls offline_access), a PKCE S256 code_challenge, state, and resource.
2. The user signs in with Google or X and approves. The browser returns to your redirect URI with a code.
3. POST https://call4.me/api/auth/oauth2/token with grant_type=authorization_code, the code, client_id, redirect_uri, code_verifier, and resource. You get a Bearer access token (JWT, valid one week) and, with offline_access, a refresh token.
4. Send `Authorization: Bearer <token>` to https://call4.me/mcp. A 401 with a WWW-Authenticate challenge means sign in (again).

MCP clients do all of this automatically when the server answers with the challenge.

## API keys

A signed-in user can also create an API key on https://call4.me/account and give it to the agent. It works as `Authorization: Bearer <key>` on https://call4.me/mcp and https://call4.me/api, or in the URL as https://call4.me/mcp/<key> for clients that cannot sign in or set headers. Creating a new key revokes the old one.

## Revocation

Access tokens expire after a week; refresh tokens rotate on use. Users revoke an API key by creating a new one on https://call4.me/account.
