# Coin IRA auth.md

## Agent audience

This file applies to automated agents that read public Coin IRA content or use the public calculator services.

## Public access method

- Authentication method: anonymous HTTPS
- Public content and REST API method: GET
- MCP transport and method: Streamable HTTP POST at https://coinira.com/mcp
- Registration endpoint: none
- Provisioning endpoint: none
- Credentials: none
- Public API Catalog: https://coinira.com/.well-known/api-catalog
- OpenAPI description: https://coinira.com/.well-known/openapi.json
- Calculator API documentation: https://coinira.com/api/docs/index.md
- MCP server: https://coinira.com/mcp
- Retirement projection limit: 30 requests per client per minute
- Historical calculator limit: 6 requests per client per minute
- MCP transport limit: 30 requests per client per minute

Agents can read public Markdown pages and call the public calculator REST APIs or MCP tools without an account. Agents must follow robots.txt, Content Signals, published service limits, and the stated calculator disclosures.

## Secure client accounts

The secure Coin IRA client account system is not an agent API. Coin IRA does not provide agent registration, delegated authorization, OAuth access, or bearer credentials for client accounts.

Agents must not automate client login, submit identity information, open an account, trade, move funds, or make changes to a client account. A person must complete those actions through the secure Coin IRA service.
