# Step 3 — Auth.md + OAuth discovery

Publish /auth.md in Markdown explaining how an agent registers, plus /.well-known/oauth-protected-resource and /.well-known/oauth-authorization-server. Include an agent_auth block and serve the RFC 8414 issuer-suffix path too — scanners fetch /.well-known/oauth-authorization-server/auth/v1 and a 404

Canonical: https://robauto.ai/learn/advanced-agentic-commerce/5

_Advanced Agentic Commerce: Ship the Full Agent Surface — lesson 5 of 20 (PLAYBOOK)_

Publish /auth.md in Markdown explaining how an agent registers, plus /.well-known/oauth-protected-resource and /.well-known/oauth-authorization-server. Include an agent_auth block and serve the RFC 8414 issuer-suffix path too — scanners fetch /.well-known/oauth-authorization-server/auth/v1 and a 404 there fails the check.

Source: [IETF RFC 8414](https://www.rfc-editor.org/rfc/rfc8414?utm_source=robauto)

[Previous lesson](/learn/advanced-agentic-commerce/4) · [Next lesson](/learn/advanced-agentic-commerce/6) · [Course overview](/learn/advanced-agentic-commerce) · [All courses](/learn)

---

(c) 2026 Robauto, Inc. — support@robauto.ai
Machine surfaces: https://robauto.ai/llms.txt · https://robauto.ai/llms-full.txt · https://robauto.ai/.well-known/api-catalog
