# HoneyRuns auth.md

How AI agents and other software get credentials for the HoneyRuns API.

## Audience

Agents and integrations acting for a HoneyRuns customer (a fleet or a shop) against the
public API at `https://api.honeyruns.com/api/v1`. Every credential belongs to one company,
and every call is scoped to that company's data.

## Registration

There is no self-serve agent registration endpoint. A person with admin access to a
HoneyRuns company provisions the credential:

1. Sign in at https://app.honeyruns.com.
2. Open **Settings → Developer** (`/admin/developers`).
3. Create an API key and give it to the agent.

An agent without a key should ask its user to create one. Don't try to sign up for an
account on the user's behalf.

## Supported methods

| Method  | Credential | How it's issued                          |
| ------- | ---------- | ---------------------------------------- |
| API key | Bearer     | Company admin, Settings → Developer     |

OAuth discovery metadata (`/.well-known/oauth-protected-resource`) is not published.

## Using the credential

Send the key as a bearer token on every request:

```http
GET /api/v1/runs HTTP/1.1
Host: api.honeyruns.com
Authorization: Bearer <api-key>
```

- API reference: https://docs.honeyruns.com
- OpenAPI spec: https://api.honeyruns.com/api/v1/openapi.json
- API catalog: https://honeyruns.com/.well-known/api-catalog

Keys can be revoked from the same Developer page. A revoked or invalid key gets `401`.
