# Suppliping auth.md

Suppliping is an invite-only, human-operated supplier communication product. This document describes the access model for reviewers, integrators, and automated agents without advertising capabilities that do not exist.

## Agent audience

This document is for automated agents assisting an organization that is evaluating Suppliping or an authorized Suppliping customer. Public discovery is read-only. An agent does not gain product access merely by reading this document.

## agent_auth

- skill: request human contact about Suppliping organization access
- register_uri: https://suppliping.com/basvuru
- registration_method: human_reviewed_access_inquiry
- automatic_registration: false
- registration_result: inquiry_record_only
- credentials_issued: false
- support_uri: https://suppliping.com/iletisim

## Public machine-readable resources

- API catalog: https://suppliping.com/.well-known/api-catalog
- OpenAPI document: https://suppliping.com/openapi.json
- Public health endpoint: https://suppliping.com/api/health

The public health endpoint supports unauthenticated HTTP GET requests. It reports only process health metadata and does not expose customer, supplier, account, conversation, or message data.

## Product access

There is no public self-service product signup or account-provisioning endpoint. Prospective organizations may submit an access inquiry at https://suppliping.com/basvuru. The form creates only an inquiry record for human follow-up; it does not create a user, approve an organization, issue credentials, or guarantee access.

This hosted product currently uses an operator-configured, authorized human account. If the operator separately offers access to an organization, the deployment and account must be configured outside the public request form. An authorized human then signs in through the browser at https://suppliping.com/giris with an email address and password. The web application establishes a browser session using a secure HTTP-only cookie. Customer-facing dashboard pages and their browser-facing APIs require that authenticated browser session.

Internal machine-to-machine routes use separate controls: scheduled jobs require an operator-managed cron secret and the WhatsApp webhook requires Meta's signature verification. Those controls are private infrastructure credentials, are not published in this catalog, and are not agent credentials.

Credentials remain under the control of the authorized human user. Agents must not ask a user to place a password, Meta access token, webhook signing secret, or session cookie into a public form or agent prompt.

## Unsupported authentication and automation

Suppliping does not publish OAuth 2.0 or OpenID Connect metadata, third-party bearer tokens, API keys, service accounts, or agent credentials. There is no public agent login flow. Automated clients must not infer or attempt OAuth, bearer-token, or API-key authentication.

Suppliping does not offer autonomous public POST, PUT, PATCH, or DELETE operations. Automated agents must not submit the access inquiry form, send WhatsApp messages, manage suppliers, change consent, or invoke other state-changing product actions. Those workflows are available only to authorized human users in the authenticated browser interface.

There is no public agent credential revocation endpoint because no public agent credentials are issued. A customer that needs browser access changed or revoked must contact support.

## Support

For product access, review questions, or integration support, use https://suppliping.com/iletisim.
