# CV API Authentication

The public read endpoints require no authentication:

- GET /api/v1/cv
- GET /cv/content
- GET /cv/meta
- GET /cv/pdf
- GET /openapi.json

Authenticated write and preview operations are owner-only and use SSO bearer tokens. Recruiting agents should not call write endpoints.

Agent auth metadata:
- Protected resource metadata: https://cv.laisky.com/.well-known/oauth-protected-resource
- Authorization server metadata: https://cv.laisky.com/.well-known/oauth-authorization-server

## Walkthrough
### Discover
Read this file and the protected resource metadata.
### Pick a method
Use no authentication for public read endpoints. Use OAuth authorization code only for owner write operations.
### Register
Public recruiting agents do not need registration. Owner tools register through the SSO server.
### Claim
Send bearer credentials only to owner-only write routes when explicitly authorized.
### Use credential
Use Authorization: Bearer for owner-only PUT /cv/content and POST /cv/pdf/preview.
### Errors
401 means the owner credential is missing or expired. Public GET routes should not require credentials.
### Revocation
Discard expired SSO tokens and redirect the owner to https://sso.laisky.com/.
