Sunny Yuen · Authentication Profile

Yuens Me Authentication

Authentication

Sunny Yuen declares 4 security scheme(s) across its OpenAPI definitions.

CompanyAI AgentsA2AMCPResumeHiringRecruitingProfessional ProfileJob MatchingOpen Source
Methods: Schemes: 4 OAuth flows: API key in:

Security Schemes

none
http
scheme: bearer
x-brain-key apiKey
· in: header ()
oauth2
· flows: , ,

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: >-
  https://github.com/yuens1002/resume-agent#security-model, the live RFC 8414 / RFC 9728 documents at
  https://agent.yuens.me/.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource,
  and anonymous probes of every public operation on 2026-09-19. openapi/yuens-me-openapi.yml declares no
  securitySchemes and no security requirement, which is accurate for the public surface, so the derive
  script produced nothing and this profile is docs-sourced.
docs: https://github.com/yuens1002/resume-agent#security-model
summary: >-
  The third-party surface is anonymous: all six REST operations, the OpenAPI document, the agent card and the
  public MCP server answered 200 with no credential. Credentials exist only for the profile owner — a Bearer
  API key on POST /resume, an x-brain-key header or an OAuth 2.0 access token on the private /mcp server —
  and they double as rate-limit bypass tokens. The OAuth authorization server on agent.yuens.me is real
  (authorization code + PKCE, client credentials, refresh token, client_secret_post on every grant) but has
  no registration endpoint and publishes no scopes: it exists so the owner's own claude.ai connector can
  authenticate, not as a developer program.
public_surface:
  scheme: none
  operations: [queryProfile, matchJob, getProfile, getAvailability, listProjects, listObservations]
  mcp_endpoint: https://agent.yuens.me/public-mcp
  verified: '2026-09-19'
  rate_limit: 30 requests per minute per IP (rate-limits/yuens-me-rate-limits.yml)
schemes:
  - id: anonymous
    type: none
    applies_to: all public REST operations and the public MCP server
    evidence: Every public path returned 200 without an Authorization header; the card declares securitySchemes {} and security [{}].
  - id: ownerBearerKey
    type: http
    scheme: bearer
    audience: profile owner
    applies_to:
      - POST /resume (tailored-resume generator; enforced when AUTH_MODE=key)
      - site-wide rate-limit bypass
    evidence: GET /resume and GET /profile returned 401 {"error":"Unauthorized"} with no WWW-Authenticate header on 2026-09-19.
  - id: brainKey
    type: apiKey
    in: header
    name: x-brain-key
    audience: profile owner
    applies_to:
      - private MCP server https://agent.yuens.me/mcp (direct API / Claude Desktop via the mcp-remote bridge)
      - site-wide rate-limit bypass
    evidence: README security model; CORS allow-headers on /public-mcp and /mcp list x-brain-key.
  - id: oauth2
    type: oauth2
    audience: profile owner's connector clients
    applies_to:
      - private MCP server https://agent.yuens.me/mcp (rate-limit bypass on /mcp only)
    flows:
      authorizationCode:
        authorizationUrl: https://agent.yuens.me/authorize
        tokenUrl: https://agent.yuens.me/token
        pkce: S256 required
        scopes: {}
      clientCredentials:
        tokenUrl: https://agent.yuens.me/token
        scopes: {}
      refreshToken:
        tokenUrl: https://agent.yuens.me/token
    token_endpoint_auth_methods: [client_secret_post]
    response_types: [code]
    resource: https://agent.yuens.me
    bearer_methods: [header]
    metadata:
      authorization_server: well-known/yuens-me-oauth-authorization-server.json
      protected_resource: well-known/yuens-me-oauth-protected-resource.json
    dynamic_client_registration: false
    scopes_published: false
    client_onboarding: >-
      The client id and secret are the operator's own OAUTH_CLIENT_ID / OAUTH_CLIENT_SECRET environment
      variables; there is no registration endpoint (GET /register 404) and no developer sign-up. Third
      parties cannot obtain an OAuth client, by design.
    evidence: >-
      /.well-known/oauth-authorization-server 200 (issuer, endpoints, grants, S256, client_secret_post);
      /.well-known/oauth-protected-resource 200; GET /authorize 400 (parameter validation), GET /token 404
      (POST-only). CHANGELOG 2026-09-16 records client_secret becoming mandatory on the authorization_code
      and refresh_token grants.
identity:
  scheme: OEP Phase 1 domain verification
  public_key: https://agent.yuens.me/.well-known/oep-public-key.json (Ed25519)
  dns_record: _oep.yuens.me TXT "v=oep1; alg=ed25519; fp=bZCBY6x_RnGLyQgnCY0lN7CvpiBZMvRUBo68oeisPYc"
  card_field: provider.identity.fingerprint
  verified: '2026-09-19'
  note: 'Proves the domain owner operates the agent; it does not authenticate callers and signs nothing yet (README: no response or card signing in Phase 1).'
mcp_auth_summary:
  public-mcp: none
  mcp: oauth2 or x-brain-key
notes:
  - Bearer credentials are also the rate-limit bypass, so a third party must not send one it was not issued; the honest posture for agents is anonymous calls under the 30 req/min ceiling.
  - No API-key issuance, no scopes, no OpenID Connect discovery (openid-configuration 404).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/yuens-me-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.