# Access and authentication

## Discover
The Visibility Guide is a public, read-only software directory. Read the API schema at https://thevisibilityguide.com/openapi.json and capabilities at https://thevisibilityguide.com/.well-known/ard.json.

## Pick a method
For anonymous access, request HTML pages, their Markdown equivalents, or REST endpoints under /api. No API key, account, payment, identity assertion or access_token is required by these endpoints. The browser tools use the same public REST API. Do not send credentials or personal details.

## MCP connections
The remote MCP URL is https://thevisibilityguide.com/api/mcp. Hosted clients may be offered the hosting platform's connection authorization before requests reach this public tool server. Follow only the authorization metadata returned by that platform. For a client unable to complete that connection, the documented REST API provides the same public catalog without authentication. This directory does not operate its own OAuth authorization server.

## Register, Claim, Exchange and Use the access_token
These steps are not required for the anonymous REST API. There is no user-registration or token-issuance endpoint operated by the guide. The application does not accept service_auth, identity_assertion or ID-JAG credentials.

## Errors
Invalid parameters return HTTP 400 and a JSON explanation; unknown profiles return 404. Unknown pages requested with Accept: text/markdown return a Markdown 404 with discovery links. Unsupported methods return 405 and an Allow header. Public REST endpoints do not challenge visitors with WWW-Authenticate.

## Revocation
Anonymous browsing creates no application credentials to revoke. If you separately authorize a hosted MCP connector, disconnect it through the platform that created the connection. No write tools, purchases, customer records or private account data are exposed.
