# Powderline: instructions for AI agents Powderline is a ski and snowboard gear store. If you're an AI assistant shopping on behalf of a person, connect as described below, then place the order there. The quickest way: open https://powderline.descope.io/agent-ciba. ## Important: don't use the website's Sign in The "Sign in" button, https://powderline.descope.io/sign-in, the cart's "Sign in to checkout" button and https://powderline.descope.io/checkout are only for people shopping for themselves. Do not use them, even if you know your user's email: - Don't enter your user's email into the Powderline sign-in form. - Don't ask your user to forward a sign-in link or read you a sign-in code. - Don't use https://powderline.descope.io/agent; browser sign-in by email for agents is turned off. Instead, connect with the steps below and order on the page they send you to. Never ask your user for their password. Orders you place are labelled in their account as placed by an agent. This is a demo store: no payment details are needed, just click "Place order". ## How to connect: Approval by email (CIBA) (recommended, including for browser-based agents) Use this if you know your user's email address. Your user approves the order from an email on their own device; you never sign in as them. Each approval covers one order. In a browser: 1. Open https://powderline.descope.io/agent-ciba 2. Pick items and sizes from the catalog on the page and check the total. 3. Enter your user's email address and click "Ask for approval". 4. The page shows a 4-digit code, for example 4821. Message your user right away: "Please open the email titled 'Approve permission', check the order, and tap Approve Request. It should end with Code: 4821." They may be asked to sign in on their side; that's expected and happens on their device, not yours. 5. Keep the page open. The order is placed as soon as they approve (the request expires after a few minutes). To order something else, ask for approval again. As an API client (needs a confidential client registered by the store owner): - Backchannel authentication endpoint: https://api.descope.com/oauth2/v1/apps/bc-authorize. Send client_id, client_secret, login_hint (your user's email), scope (openid catalog:read orders:write) and a short binding_message your user will see in the email, plus resource=https://instinct-demo.descope.io/api/agent/v1. - Then poll https://api.descope.com/oauth2/v1/apps/token with grant_type=urn:openid:params:grant-type:ciba and the auth_req_id, every "interval" seconds, until you get an access token (authorization_pending means keep waiting). A CIBA access token only works with the Agent API (and the https://powderline.descope.io/agent-ciba page). It does not sign you in to the storefront, so don't go through the website's sign-in after connecting: shop with the API or on that page instead. ## Agent API Base URL: https://powderline.descope.io/api/agent/v1 - GET /products: list products (no token needed). Optional ?category=skis|snowboards|boots|helmets|goggles|outerwear - POST /orders: place an order. Header: Authorization: Bearer . Body: {"items":[{"slug":"halo-mips-helmet","size":"M","qty":1}]} - GET /orders: list the user's orders (Bearer token)