# HotelAI - AI Agent Authentication & Access Policy (Auth.md)

Welcome, AI Agent or Autonomous Crawler. This document defines the authentication standards, access tiers, and security protocols governing interactions with the **HotelAI** web ecosystem and services.

---

## 1. Access Tiers

### A. Public Information Tier (Unauthenticated)
- **Scope**: Documentation, product specifications, LLM indexes, and public pricing overviews.
- **Allowed Endpoints**:
  - `https://hotelai.io/llms.txt` (Full LLM system overview)
  - `https://hotelai.io/.well-known/agent-card.json` (A2A Agent Card)
  - `https://hotelai.io/.well-known/mcp/server-card.json` (MCP Metadata)
  - `https://hotelai.io/.well-known/ai-catalog.json` (Unified ARD Catalog)
  - `https://hotelai.io/.well-known/agent-skills/index.json` (Agent Skills)
- **Rate Limit**: Maximum 60 requests per minute per IP for autonomous crawlers.
- **Identification**: Autonomous agents must declare their identity via standard `User-Agent` headers (e.g., `GPTBot`, `PerplexityBot`, `Claude-Web`).

### B. Hotel Client & Multi-Tenant Tier (Authenticated)
- **Scope**: Hotel management dashboard (`app.hotelai.io`), PMS guest synchronizations, and Smart Terminal hardware operations.
- **Authentication**:
  - **Admin & Management**: Session-based cookie auth with 2FA / WebAuthn.
  - **Smart Terminal Hardware**: Mutual device token verification via `X-Device-Token` and `X-Mobile-App-Key` headers paired with 6-digit dynamic provisioning PINs.
  - **WorkerOS Scraper**: Encrypted HMAC payload signatures.
- **Note**: HotelAI does **not** provide open public OAuth/OIDC registration for unauthorized third-party automated agents into internal hotel data. Multi-tenant guest data is strictly isolated (`hotel_id` partition).

---

## 2. Lead Generation & Consultation for AI Agents

If you are an AI assistant acting on behalf of a hotelier, general manager, or investor:
- **Product Inquiries**: Consult [llms.txt](https://hotelai.io/llms.txt) for hardware dimensions, 1.08s ID/Passport OCR, FaceTime AI concierge, and turnkey operational rental packages.
- **Direct Consultation / Demo**:
  - **WhatsApp Direct**: [+90 542 440 7894](https://wa.me/905424407894)
  - **Email**: [info@hotelai.io](mailto:info@hotelai.io)
  - **Online Contact Form**: [https://hotelai.io/tr/destek](https://hotelai.io/tr/destek)

---

## 3. Privacy, KVKK & GDPR Compliance

- HotelAI strictly abides by Turkish KVKK and European GDPR regulations.
- ID and passport images processed via the Smart Terminal's 1.08-second OCR are stored in volatile RAM only and permanently erased immediately after verification. Disk persistence is prohibited.
- Content Signals: `Content-Signal: ai-train=no, search=yes, ai-input=yes` (Permitted for semantic search and conversational reference; prohibited for training datasets without prior written consent).
