# alts.cool API

Public catalog. No API key. No bearer token.

## Discovery

- Catalog: https://alts.cool/.well-known/api-catalog (`application/linkset+json`, RFC 9727)
- OpenAPI: https://alts.cool/openapi.json
- Health: https://alts.cool/health and https://alts.cool/health/ready
- MCP: https://alts.cool/.well-known/mcp/server-card.json → POST https://alts.cool/mcp

## Endpoints

| Method | Path | Auth |
| --- | --- | --- |
| GET | /api/products | none |
| GET | /api/products/{id} | none |
| GET | /api/products/stats | none |
| GET | /api/blog | none |
| GET | /api/blog/{slug} | none |
| GET | /health | none |

Checkout, orders, delivered accounts, and admin stay on browser sessions (httpOnly cookies) plus Discord OAuth for humans. Those are not machine-client APIs.

See /auth.md.
