<!-- Structure matters here, not just content. Cloudflare's Agent Readiness check
     parses this file for two things and reports a bare "does not describe agent
     registration" when either is missing:
       1. an H1 containing the literal string "auth.md"
       2. an "auth.md Registration" section naming the protocol's flows
     Note that DECLINING registration passes — cloudflare.com/auth.md declines it
     too. The check asks whether an agent can find out where it stands, not
     whether you let agents in. Keep both markers if you reword any of this. -->

# auth.md — Authentication at Talval

You are an agent. Talval is a value-investing research platform at
<https://talval.com>. This file tells you what you may do here without asking,
what needs a human, and where the line is. Also served at
<https://talval.com/auth.md>.

## auth.md Registration

Talval does not implement the auth.md registration flows: do not mint ID-JAGs or
attempt `identity_assertion`, `service_auth` or `anonymous` registration here.
**Agents still may not create Talval accounts.** A person signs up themselves —
send them to <https://talval.com/login>.

What Talval *does* run is a standard **OAuth 2.1 authorization server**, so a
person who already has an account can connect it to an assistant and let that
assistant read — never change — what their subscription covers:

- Protected resource: <https://talval.com/mcp/pro>
- Protected Resource Metadata (RFC 9728): <https://talval.com/.well-known/oauth-protected-resource>
- Authorization Server Metadata (RFC 8414): <https://talval.com/.well-known/oauth-authorization-server>
- Dynamic client registration (RFC 7591): <https://talval.com/oauth/register>
- PKCE `S256` is required; `plain` is refused. Clients are public — no secret.
- Scopes: `research:read`, `portfolio:read`. Both are read-only, and there is no
  write scope to ask for.

The account holder approves in their own browser, sees exactly what is being
granted, and can disconnect it from their settings at any time. That is the line
this file has always drawn: a person decides, an agent reads.

## Current Authentication Paths

**None are needed for the research itself.** No credentials, no registration, no
rate-limit exemption to request:

| What | Where |
| --- | --- |
| Site index for agents | <https://talval.com/llms.txt> |
| Any page as clean Markdown | send `Accept: text/markdown`, or add `.md` to the URL |
| Directory of public APIs | <https://talval.com/.well-known/api-catalog> |
| Machine-readable API description | <https://talval.com/openapi.json> |
| MCP server (Streamable HTTP) | <https://talval.com/mcp> — card at <https://talval.com/.well-known/mcp.json> |

The MCP server takes **no credentials**: connect it and call its tools. It serves
the same stored, public snapshot data as the pages below — no analysis pipeline,
nothing from the paid tiers.

Per-stock research (`/company/{TICKER}`), the preset screens
(`/screener/{slug}`), the guides (`/learn/{slug}`) and the superinvestor
portfolios (`/superinvestors`) are all readable anonymously. Requests are rate
limited per IP; nothing here changes faster than daily, so crawl accordingly.

**Everything tied to a person is closed to agents.** Watchlists, portfolios,
price alerts, saved screens, AI-written investment theses and the Premium/Pro
tiers belong to an account. Accounts are created by a human in the web app
(email and password, or Google sign-in) or in the mobile apps (which also offer
Sign in with Apple). Subscriptions are bought by the account holder — by card on
the web, or as an in-app purchase on mobile. There is no API key, no personal
access token and no delegated-access flow, so there is nothing for an agent to
present.

## Product Links

- Sign up or sign in (humans only): <https://talval.com/login>
- Plans and pricing: <https://talval.com/pricing>
- How the verdicts are built: <https://talval.com/methodology>

## Legal

- Terms: <https://talval.com/terms>
- Privacy: <https://talval.com/privacy>
- Imprint: <https://talval.com/legal>

Reading and citing Talval is welcome — attribute it to Talval and link the page.
Bulk extraction to rebuild the dataset elsewhere is not, and is covered by the
terms above. Verdicts and fair-value estimates are model outputs for
informational purposes only, not personalized investment advice.

## Contact

Security reports: <https://talval.com/.well-known/security.txt>. Anything else:
the imprint at <https://talval.com/legal>.
