# Authentication

Canonical: https://goodrecmovies.com/auth.md · Machine guide: https://goodrecmovies.com/llms.txt

goodrecmovies is a read-only public ranking: every page, the Markdown
representations, the MCP tools, and the /ask endpoint work without any
credentials. There is no API key, no OAuth flow, and no agent registration —
do not send Authorization headers; they are ignored.

## Discover

Agents discover auth requirements from this file and from
/.well-known/oauth-protected-resource (RFC 9728). Both say the same thing:
reads are anonymous.

## Pick a method

The only method is "no method" — fetch directly. There is no second method
to pick from and no credentials to compare.

## Methods

- **Anonymous reads (default).** Fetch any URL directly. Rate limits apply
  per-IP exactly as they do to browsers; back off on 429 and retry after
  Retry-After.
- **Signed-in user features** (bookmarks, watched lists) are browser-only
  Google Sign-In for human visitors. Agents cannot and should not create
  accounts: everything an agent needs is available anonymously.

## Revocation

Nothing to revoke: no tokens are issued, so none can be revoked. If that
ever changes, this file is where the mechanism will be documented first.

## Errors

- 404 — the title id or path does not exist in the corpus.
- 429 — rate limited; wait for Retry-After.

There is no token to claim, exchange, or revoke. If a future API adds auth,
this file and /.well-known/oauth-protected-resource will describe it here
first.
