# Loonaut authentication (auth.md)

The REST API (https://loonaut.com/api/v1) and the MCP server (https://loonaut.com/mcp) need no account and no API key.
Loonaut has no OAuth server and no agent registration.

## Discover

Read https://loonaut.com/.well-known/oauth-protected-resource.

- `resource` is https://loonaut.com.
- `authorization_servers` is empty. No authorization server exists.
- `bearer_methods_supported` is empty. Loonaut accepts no bearer token.

The file https://loonaut.com/.well-known/oauth-authorization-server does not exist.
The OpenAPI document declares `security: []` at the top level. The read operations name no security scheme. An operation that needs a credential names its scheme.
The MCP server card declares `authentication.type: "none"`.

## Pick a method

Use MCP (Streamable HTTP, JSON-RPC 2.0) at https://loonaut.com/mcp, or use REST under https://loonaut.com/api/v1.
Send no Authorization header, API key or cookie.

## Use

```http
GET /api/v1/toilets/nearest?lat=49.8728&lon=8.6512&limit=5 HTTP/1.1
Host: loonaut.com
Accept: application/json
```

The limit is 60 requests per minute per IP. The map area endpoint `GET /api/v1/toilets` has its own limit of 300. The `RateLimit` headers show the state.

## Errors

REST errors use `application/problem+json` with `type`, `title`, `status` and `detail`. Some add `invalid_params` or `retry_after_seconds`.
MCP uses JSON-RPC errors for protocol faults and `isError` results for tool faults.

- 429: wait for `Retry-After`, then send the request again.
- 503: the database is busy for a moment. Wait for `Retry-After`, then send the request again.
- 400: read `invalid_params` and correct the request.

## Revocation

Loonaut issues no credentials. Nothing needs revocation.
