# auth.md — www.vistudio.ro

Access rules of https://www.vistudio.ro for AI agents and MCP clients.

## Audience

AI agents, crawlers and MCP clients that read the content of https://www.vistudio.ro, and agents that a person authorises to manage it.

## Reading

Reading needs no credentials and no registration. Everything published on this site is public:

- MCP server (read-only, Streamable HTTP): https://www.vistudio.ro/mcp
- Overview for language models: https://www.vistudio.ro/llms.txt
- Any page as Markdown: request the page URL with `Accept: text/markdown`, or add `?format=md`.

## Credentials

This domain never accepts credentials. Do not send an `Authorization` header, API keys, tokens or cookies to
www.vistudio.ro. Sign-in and consent exist only on app.vistudio.ro.

## Managing content

The content is managed on the platform admin, https://app.vistudio.ro, never on this domain.

- MCP server: https://app.vistudio.ro/mcp
- OAuth protected resource metadata: https://app.vistudio.ro/.well-known/oauth-protected-resource
- OAuth authorization server metadata: https://app.vistudio.ro/.well-known/oauth-authorization-server
- Client registration: https://app.vistudio.ro/oauth/register (dynamic client registration, RFC 7591)
- Flow: OAuth 2.1 authorization code with PKCE (`S256`), with `resource=https://app.vistudio.ro/mcp`.
- Scopes; the authoritative list is `scopes_supported` in the authorization server metadata:
  - `mcp:read`: read the structure and content of the sites where the person has a role, including drafts.
  - `mcp:write`: create and edit pages, posts, sections, media, forms, SEO, redirects and translations; changes to pages and posts stay drafts by default.
  - `mcp:publish`: publish or unpublish pages and posts; this is the explicit step after the person has reviewed the draft.
  - `mcp:admin`: menus, site settings and texts, the homepage, languages, form recipients and submissions, redirect imports and agent sessions; most of these tools also need the admin role on the site.
- Without `scope` in the authorization request all four are requested, and the person can untick any of them at consent. A token never goes beyond the role of the person on the site.
- API keys are accepted only at app.vistudio.ro, never at www.vistudio.ro.

## Accounts

Accounts are created by the administrators of the platform. There is no agent self-registration: an agent acts for a
person who has an account for this site. Site id on the platform: `vistudio`.
