# RankRope Authentication & API Access Protocol (auth.md)
> Developer, AI agent, and LLM access specification for RankRope (https://rankrope.com).
> Updated: 2026-10-09T14:57:46.126Z

---

## 1. Public Read-Only Access (Zero Auth / Open APIs)
All AI models (ChatGPT, Claude, Perplexity, Grok, Gemini), autonomous agents (Cursor, Windsurf, Claude Desktop, Antigravity), and developer tools can query public data without API keys, registration, or rate limiting walls.

### Unrestricted Public Endpoints:
- **Leaderboard API**: `GET https://rankrope.com/api/leaderboard?period=all_time&limit=20`
- **Products API**: `GET https://rankrope.com/api/products?q=search_term`
- **Single Product API**: `GET https://rankrope.com/api/products?slug={slug}`
- **MCP JSON-RPC Server**: `POST https://rankrope.com/api/mcp`
- **AI Snapshot Summary**: `GET https://rankrope.com/api/ai-snapshot`
- **OpenAPI 3.1.0 Spec**: `GET https://rankrope.com/api/openapi.json`
- **LLMs Standard Index**: `GET https://rankrope.com/llms.txt`
- **LLMs Full Knowledge Base**: `GET https://rankrope.com/llms-full.txt`
- **Markdown Product Catalog**: `GET https://rankrope.com/catalog.md`
- **Single Product AI Markdown**: `GET https://rankrope.com/p/{slug}.md`
- **Dynamic Rank Badge SVG**: `GET https://rankrope.com/badge/{slug}.svg`

---

## 2. Maker Authentication (Web Dashboard & Magic Link)
Makers managing their listed software use secure passwordless magic link authentication powered by Supabase Auth:
- **Endpoint**: `POST https://rankrope.com/api/auth/magic-link`
- **Headers**: `Content-Type: application/json`
- **Payload**:
  ```json
  {
    "email": "maker@example.com"
  }
  ```
- **Session Tokens**: Returned via secure HTTP-only cookie (`sb-access-token`) or bearer Authorization token in API headers:
  `Authorization: Bearer <JWT_TOKEN>`

---

## 3. Product Submissions & Ranking Climb Transactions
RankRope uses financial skin-in-the-game verification for all product creation and rank climbing operations.

- **Launch Checkout Initiation**:
  `POST https://rankrope.com/api/checkout/create-session`
  - Body:
    ```json
    {
      "product_name": "My AI Tool",
      "website_url": "https://example.com",
      "category": "ai-agents-infrastructure",
      "amount_usd": 50
    }
    ```
  - Response returns a Stripe Checkout URL.
- **Verification Receipts**:
  Upon successful payment, an immutable cryptographically verifiable receipt is generated at:
  `https://rankrope.com/receipt/{receipt_id}`

---

## 4. Model Context Protocol (MCP) Agent Access
The RankRope MCP server at `https://rankrope.com/api/mcp` accepts standard JSON-RPC 2.0 requests over HTTP. No bearer tokens or credentials are required for MCP read tools.

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_leaderboard",
    "arguments": {
      "period": "all_time",
      "limit": 10
    }
  }
}
```

---

## 5. Webhook Security
Platform webhook notifications (e.g. Stripe checkout events) are authenticated via HMAC-SHA256 signature verification:
- Header: `stripe-signature`
- Signature validation is performed against the environment webhook secret before mutating product ranks.

---

## 6. Support & Inquiries
- Security Team: `support@rankrope.com`
- Terms of Service: https://rankrope.com/terms
- Privacy Policy: https://rankrope.com/privacy
