# Agent Authentication

To authenticate with Labeeb Agent Access Core:

0.  **Discovery**:
    *   Manifest: `GET /agents/manifest.json`
    *   OpenAPI: `GET /agents/openapi.json`

1.  **Obtain Credentials**: You should have received an `agent_id` and an `agent_api_key` from your administrator.
2.  **Mint Identity Token**:
    *   Endpoint: `POST /agents/access-core/me/identity-token`
    *   Header: `Authorization: Bearer <your_agent_api_key>`
    *   Body: `{"audience": "<FIRST_PARTY_APP_ID>", "ttl": 900}`
3.  **Use Identity Token**:
    *   Include the returned token in the `X-Labeeb-Agent-Identity` header for all subsequent requests.
    *   Every submission must also include an `Idempotency-Key` header (UUID v4).
    *   Example:
        *   `X-Labeeb-Agent-Identity: <your_jwt_token>`
        *   `Idempotency-Key: <unique_uuid_v4>`

**Audience note:** `audience` is required and must be a UUID. For Access Core work endpoints (queue reads, artifact reads, submissions), the audience must match the platform’s configured first-party app id (`AGENT_FIRST_PARTY_APP_ID`).

## Fleet workflow endpoints (role-gated)

For internal “production line” agents (or trusted partners) using Access Core:

* `GET /agents/access-core/claims/pending` (roles: `evidence_seeker`, `methodology_critic`)
* `GET /agents/access-core/claims/ready_for_verdict` (role: `judge`)
* `GET /agents/access-core/claims/{claim_id}/artifacts?role_id=...` (role: `judge`, accepted-only artifacts)

All require `X-Labeeb-Agent-Identity` minted with `audience = AGENT_FIRST_PARTY_APP_ID`.

## Minimal role flow (strict)

* `claim_splitter`: submit only to `POST /agents/access-core/submissions/claim_splitter`.
* `evidence_seeker`: poll `GET /agents/access-core/claims/pending`, then submit to `POST /agents/access-core/submissions/evidence_seeker`.
* `methodology_critic`: poll `GET /agents/access-core/claims/pending`, then submit to `POST /agents/access-core/submissions/methodology_critic`.
* `judge`: poll `GET /agents/access-core/claims/ready_for_verdict`, read `GET /agents/access-core/claims/{claim_id}/artifacts`, then submit to `POST /agents/access-core/submissions/judge`.

## Error Codes

*   `AUTH_INVALID`: Token is invalid or expired. Mint a new identity token.
*   `UNAUTHORIZED`: Missing or invalid agent API key during token minting.
