# Australia Wide First Aid auth.md

This file is for AI agents and assistants helping someone find and book first aid or CPR training with Australia Wide First Aid (RTO 31961). It explains how to access the site's agent surfaces. The short answer: there is nothing to authenticate. Every agent surface here is public and read-only, and needs no credentials, API key, account or registration.

## Discover

These are the public agent surfaces. None of them needs credentials.

- Agent API: `https://www.australiawidefirstaid.com/agent/`, read-only JSON endpoints under this base, such as `/agent/courses`, `/agent/locations`, `/agent/sessions` and `/agent/faqs`.
- [OpenAPI description](https://www.australiawidefirstaid.com/agent/openapi.json): the agent API's OpenAPI 3.1 description, its parameters, responses and errors.
- [API documentation](https://www.australiawidefirstaid.com/agent/docs): the agent API and the MCP server described for people.
- [API catalog](https://www.australiawidefirstaid.com/.well-known/api-catalog): the RFC 9727 catalog naming the agent API and the MCP server.
- MCP server: `https://www.australiawidefirstaid.com/mcp`, MCP over Streamable HTTP with the agent API's tools plus `start_booking`. Add it to an assistant as a custom connector; there is no sign-in.
- [MCP server card](https://www.australiawidefirstaid.com/mcp/server-card): describes the MCP server; also at `/.well-known/mcp/server-card.json`, with a manifest at `/.well-known/mcp.json`.
- A2A agent: `https://www.australiawidefirstaid.com/a2a`, a read-only A2A agent (JSON-RPC) with the course, venue, session and FAQ skills.
- [A2A agent card](https://www.australiawidefirstaid.com/.well-known/agent-card.json): describes the A2A agent and its skills.
- [Agent Skills index](https://www.australiawidefirstaid.com/.well-known/agent-skills/index.json): the Agent Skills discovery index, listing each SKILL.md with its URL and SHA-256 digest.
- [ARD catalog](https://www.australiawidefirstaid.com/.well-known/ard.json): the Agentic Resource Discovery catalog of the resources above, with the site's did:web identity.
- [WebMCP tools](https://www.australiawidefirstaid.com/): in a browser, every page offers WebMCP tools for finding courses and sessions and starting a booking.
- [llms.txt](https://www.australiawidefirstaid.com/llms.txt): the site's index for agents, with every course and location.

## Pick a method

Anonymous access is the only method. Call any surface above directly and send no `Authorization` header. There is no other method to choose from.

## Register

You don't need to register, and you can't: there is no agent registration, client registration or sign-up for agents.

## Credentials

No credentials exist for agents. There are no API keys, tokens or client secrets, so there is nothing to claim, exchange, send, refresh or revoke. Don't ask the person for a password or a key for this site.

## Booking and payment

No agent surface books a place, takes personal details or takes payment. Searching gives you a session, and `start_booking` hands it to the person: over MCP it returns a booking link for them to open, and in a browser the WebMCP tool opens the booking in their tab. Either way the person confirms and finishes on the enrolment site, where they enter their own details and pay themselves.

- Agents must not enter payment details for someone.
- Agents must not tell the person a booking is complete before they finish on the enrolment site.
- For a group or workplace booking, send the person to [the corporate page](https://www.australiawidefirstaid.com/corporate).

## Errors

No request is refused for missing credentials: you will never get a 401 or a `WWW-Authenticate` challenge. The agent API answers errors as JSON `{"error": "..."}` with status 400 (bad arguments), 404 (unknown course, location or session), 409 (an ambiguous course or location, with `candidates`) or 502 (an upstream lookup is unavailable; try again shortly). The [API documentation](https://www.australiawidefirstaid.com/agent/docs) describes each one.

## Changes

If an account feature, such as a person viewing their own bookings, is ever offered to agents, this file is where it will be described. Until then, everything here stays public.
