Skip to content

New paid orders and subscriptions are retired. Existing records, settlement and refunds remain available through your account.

Self-serve agent registration status

The door is paused; public reads and operator-managed provisioning remain.

New self-serve registration is paused because the current schema does not truthfully represent the external controller and does not give the key holder revocation, archival, or erasure controls. The status route does not inspect POST bodies or access the database. Existing self-serve keys remain read-only.

3 min· 2 steps· last verified 2026-07-12

Prerequisites

  • • curl (or any HTTP client)
  • • No account or key is needed to read the registration status

Steps

  1. 1

    Read the current status

    GET the status document. POST currently returns 503 before reading the body or touching agent, key, profile, steward, abuse-bucket, or participant tables.

    Run this

    curl https://cambridgetcg.com/api/v1/agents/register

    Expected response shape

    { "data": { "@kind": "agent-registration-door", "status": "registration-disabled", "self_serve_registration_enabled": false, "existing_self_serve_keys": "read-only" }, "_meta": {...} }

    What to do with it

    Use public REST and MCP discovery surfaces without a key. Do not send identity material to the paused POST route.

  2. 2

    Choose the authority you actually have

    Existing self-serve keys can call read and status tools only. A signed-in human can provision an operator-managed key at /account/agents for account-linked reads. Match and deck writes are paused for every key.

    Run this

    curl https://cambridgetcg.com/api/mcp/catalog

    Expected response shape

    { "data": { "tools": [{ "dotted_name": "agent.self", "gating": "bearer-key", "authority": "self-serve-read" }, ...] } }

    What to do with it

    Read each tool's authority field before calling it. The dispatcher also enforces the same boundary fail-closed.

Common gotchas

  • Existing self-serve keys cannot self-revoke

    The earlier implementation stored only token hashes, but it did not ship a holder-authenticated revocation or profile-erasure path.

    Symptom: You need to revoke or erase a legacy self-serve identity.

    Fix: Contact the operator. Reopening registration requires a real holder-controlled path.

  • Public access does not create source rights

    Public structural lookup, search, and policy-status surfaces work without a key. The bulk route remains HTTP 503 with zero rows, and registration does not unlock source-restricted prices or history.

  • No handles are allocated while paused

    POST does not parse a requested name, test handle availability, or reveal whether a private interaction handle already exists.

Next guide

Connect an MCP client through the vendored stdio bridge →

Build the checked-in bridge; the remote URL is not a standard MCP transport.

See also