# Powderline: instructions for AI agents Powderline is a ski and snowboard gear store. If you're an AI assistant shopping on behalf of a person, connect using one of the options below, then place the order there. The quickest way: open https://instinct-demo.descope.io/agent-ciba and follow Option 1. ## Important: don't use the website's Sign in The "Sign in" button, https://instinct-demo.descope.io/sign-in, the cart's "Sign in to checkout" button and https://instinct-demo.descope.io/checkout are only for people shopping for themselves. Do not use them, even if you know your user's email: - Don't enter your user's email into the Powderline sign-in form. - Don't ask your user to forward a sign-in link or read you a sign-in code. - Don't use https://instinct-demo.descope.io/agent; browser sign-in by email for agents is turned off. Instead, connect with Option 1 (recommended) or Option 2 below and order on the page they send you to. Never ask your user for their password. Orders you place are labelled in their account as placed by an agent. This is a demo store: no payment details are needed, just click "Place order". ## Option 1: Approval by email (CIBA) (recommended, including for browser-based agents) Use this if you know your user's email address. Your user approves you from an email on their own device; you never sign in as them. In a browser: 1. Open https://instinct-demo.descope.io/agent-ciba 2. Enter your user's email address and click "Send approval request". 3. The page shows a code like PWD-1234. Message your user right away: "Please open the email titled 'Approve permission' and tap Approve Request. It should show PWD-1234." They may be asked to sign in on their side; that's expected and happens on their device, not yours. 4. Keep the page open. It continues on its own once they approve (the request expires after a few minutes). 5. The page then lists the whole catalog. Pick items and sizes, check the total, and click "Place order". As an API client (needs a confidential client registered by the store owner): - Backchannel authentication endpoint: https://api.descope.com/oauth2/v1/apps/bc-authorize. Send client_id, client_secret, login_hint (your user's email), scope (openid catalog:read orders:write) and a short binding_message your user will see in the email, plus resource=https://instinct-demo.descope.io/api/agent/v1. - Then poll https://api.descope.com/oauth2/v1/apps/token with grant_type=urn:openid:params:grant-type:ciba and the auth_req_id, every "interval" seconds, until you get an access token (authorization_pending means keep waiting). ## Option 2: OAuth (for agents that can act as an OAuth client) Use this if you connect to services with OAuth 2.0 and call their APIs. - Authorization server metadata: https://api.descope.com/v1/apps/P3JyIb3HyP57oC89Rb30X4yA08WP/.well-known/oauth-authorization-server - Protected resource metadata: https://instinct-demo.descope.io/.well-known/oauth-protected-resource - Authorization endpoint: https://api.descope.com/oauth2/v1/apps/authorize - Token endpoint: https://api.descope.com/oauth2/v1/apps/token - Client ID (public client, no secret). Use your own if listed, so orders are labelled with your name: - Muse: UDNKeUliM0h5UDU3b0M4OVJiMzBYNHlBMDhXUDpUUEEzSnlwZVNGaUR2UjRHWUFLN1phaFRuU0NoaGkj - Any other agent: UDNKeUliM0h5UDU3b0M4OVJiMzBYNHlBMDhXUDpUUEEzSnlQdkZEWFd6TGhGUnZRcUpnUUE3WnhSOTcj - Grant: authorization code with PKCE (S256) - Scopes: openid catalog:read orders:write - Resource (send as the "resource" parameter on authorize and token requests): https://instinct-demo.descope.io/api/agent/v1 - API (OpenAPI spec): https://instinct-demo.descope.io/api/agent/v1/openapi.json Your redirect URL must be registered with Powderline. If you get "Redirect URL does not match the approved redirect urls", ask your user to contact the store owner. To try the OAuth flow in a browser without writing a client, open https://instinct-demo.descope.io/agent-oauth and click a Connect button. Once connected, that page lists the whole catalog: pick items and sizes, check the total, and place the order there. An OAuth or CIBA access token only works with the Agent API (and the https://instinct-demo.descope.io/agent-oauth and https://instinct-demo.descope.io/agent-ciba pages). It does not sign you in to the storefront, so don't go through the website's sign-in after connecting: shop with the API or on those pages instead. ## Agent API Base URL: https://instinct-demo.descope.io/api/agent/v1 - GET /products: list products (no token needed). Optional ?category=skis|snowboards|boots|helmets|goggles|outerwear - POST /orders: place an order. Header: Authorization: Bearer . Body: {"items":[{"slug":"halo-mips-helmet","size":"M","qty":1}]} - GET /orders: list the user's orders (Bearer token)