Fortify Development
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
Generate, validate, and explain auth.md files — the open protocol for AI agent registration.
$ npx skills add fabricioctelles/skills --skill auth-md -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install fabricioctelles/skills auth-md --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auth-md .claude/skills/auth-md && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auth-md" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/auth-md into .claude/skills/auth-md/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-md", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/fabricioctelles/skills/tree/main/skills/auth-mdType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add fabricioctelles/skills --skill auth-md -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install fabricioctelles/skills auth-md --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/auth-md .agents/skills/auth-md && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auth-md" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/auth-md into .agents/skills/auth-md/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-md", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add fabricioctelles/skills --skill auth-md -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install fabricioctelles/skills auth-md --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/auth-md .cursor/skills/auth-md && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auth-md" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/auth-md into .cursor/skills/auth-md/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-md", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/fabricioctelles/skills.git --path skills/auth-md--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add fabricioctelles/skills --skill auth-md -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install fabricioctelles/skills auth-md --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/auth-md .gemini/skills/auth-md && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auth-md" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/auth-md into .gemini/skills/auth-md/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-md", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install fabricioctelles/skills auth-mdInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add fabricioctelles/skills --skill auth-md -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/auth-md .github/skills/auth-md && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auth-md" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/auth-md into .github/skills/auth-md/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-md", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add fabricioctelles/skills --skill auth-md -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install fabricioctelles/skills auth-md --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/auth-md .opencode/skills/auth-md && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auth-md" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/auth-md into .opencode/skills/auth-md/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auth-md", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auth-mdGenerate, validate, and explain auth.md files — the open protocol for AI agent registration.
Auth Md is an agent skill from fabricioctelles/skills. Generate, validate, and explain auth.md files — the open protocol for AI agent registration. Use when making apps agent-ready, generating Protected Resource Metadata (RFC 9728), validating auth.md files, or implementing agent registration endpoints. Triggers on "auth.md", "agent registration", "agent auth", "make my app agent-ready", "ID-JAG", "identityassertion", "serviceauth", "protected resource metadata", "agentic registration".
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/example-auth-md.md`, `references/implementation-guide.md` and `references/metadata-schema.md`).
It sits in Backend & APIs, covering OAuth and OpenID Connect. The repository describes itself as: A collection of skills for AI agents (Kiro, Cursor, Windsurf, Claude Code, and others). Each skill is a reusable module that teaches the agent to perform complex tasks with… The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f1de632. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
workos.comisitagentready.comservice.comauth-md.comraw.githubusercontent.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auth Md loads about 4.4k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 1,763 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from fabricioctelles/skills at commit f1de632, republished under its Apache-2.0 licence (© fabricioctelles). 1,763 words, ~4,402 tokens.
.claude/skills/auth-md/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Generate, validate, and explain the auth.md protocol — the open standard that lets AI agents register for services on behalf of users, without signup forms.
auth.md is a Markdown file published at a service's root (typically https://service.com/auth.md) that instructs agents on how to register. It works simultaneously as human-readable documentation and as a discoverable runtime artifact for agents.
The protocol extends RFC 9728 (OAuth 2.0 Protected Resource Metadata) with an agent_auth block in the Authorization Server metadata. Registration returns an identity_assertion (service-signed JWT) that the agent exchanges at /oauth2/token for an access_token. Three registration methods are supported:
| Flow | Mechanism | When to use |
|---|---|---|
| identity_assertion | Provider signs an ID-JAG (with auth_time) asserting user identity. Service verifies JWKS, returns identity_assertion. Agent exchanges at /oauth2/token. | Service does JIT provisioning from OIDC/SAML; wants zero-friction registration. |
| service_auth | Email hint + browser-based ceremony. Agent receives user_code + verification_uri; user signs in and types code. Agent polls /oauth2/token. | Agents on platforms that can't mint ID-JAGs; self-serve without trust list. |
| anonymous | No identity upfront. Immediate identity_assertion with pre-claim scopes. Optional deferred claim for scope upgrade. | Agent needs basic access immediately; human ownership binding deferred. |
| Endpoint | Purpose |
|---|---|
/.well-known/oauth-protected-resource | Discovery — resource metadata (RFC 9728) |
/.well-known/oauth-authorization-server | Discovery — AS metadata with agent_auth block |
POST /agent/identity | Registration — dispatches on type field |
POST /agent/identity/claim | Claim initiation (anonymous deferred, or re-initiate expired user_code) |
POST /oauth2/token | Token exchange (JWT-bearer grant) + claim polling (claim grant) |
POST /oauth2/revoke | Credential-layer revocation (RFC 7009) |
events_endpoint | Registration-layer revocation (receives SETs, RFC 8935) |
Registration never returns an access_token directly. The flow is:
identity_assertion (service-signed JWT, reusable until expiry)POST /oauth2/token with grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer → access_tokenidentity_assertion when access_token expiresThe claim ceremony uses RFC 8628-style device authorization:
user_code + verification_uri in a claim blockverification_uri, signs in to the service, types the 6-digit codePOST /oauth2/token with grant_type=urn:workos:agent-auth:grant-type:claim + claim_tokenaccess_token + fresh identity_assertion| Parameter | Default | Description |
|---|---|---|
mode | generate | generate = create auth.md + metadata; validate = check existing auth.md; explain = explain the protocol |
validation_level | basic | basic = structure + fields + consistency (offline); full = basic + live endpoint fetch |
flows | all | Which flows to include: identity_assertion, service_auth, anonymous, all |
role | app | Perspective: app = service accepting registrations; provider = platform minting ID-JAGs |
Look for:
idJagMaxAuthAgeSeconds value (default: 3600)Produce three artifacts:
a) auth.md — Markdown file following the protocol template (see references/protocol-template.md). Must contain:
b) oauth-protected-resource.json — JSON for /.well-known/oauth-protected-resource with resource_name and resource_logo_uri
c) oauth-authorization-server.json — JSON for /.well-known/oauth-authorization-server with:
issuer, token_endpoint, revocation_endpoint, grant_types_supportedagent_auth block with identity_endpoint, claim_endpoint, events_endpoint"Next Steps" section with:
auth.md at the domain rootWWW-Authenticate header to 401 responses/oauth2/tokenWhen the user is an agent provider (not an app), generate:
auth_timeresource_name + resource_logo_uri)From a local file path or URL.
Basic (offline):
identity_endpoint, token_endpoint, grant_types_supportedidentity_types_supported in metadata JSONFull (live):
/.well-known/oauth-protected-resource from the declared base URLagent_auth block exists in AS metadata/.well-known/oauth-authorization-server and verify consistencyidentity_endpoint, token_endpoint, revocation_endpoint respond (accept 400/401/422, reject 404/405)WWW-Authenticate containing resource_metadataChecklist with ✅/❌ per rule, grouped by category:
Include severity: 🔴 Error (agents will fail), 🟡 Warning (degraded experience), 🟢 Info (suggestion).
See references/validation-rules.md for the complete ruleset.
When the user wants to understand the protocol without generating or validating:
The identity_assertion flow needs to decide which service user a registration represents. Recommended resolution order:
(iss, sub) has a delegation on file, route to same user(iss, sub) delegation → interaction_required (401) with claim block for user to confirm linkingReject ID-JAGs with neither a verified email nor a verified phone — there's no basis for matching.
The /agent/identity endpoint is unauthenticated for anonymous registration. Implement two tiers:
Also rate-limit /oauth2/token polling — enforce interval from the claim block, reject with slow_down if too fast.
| Event | When | Data |
|---|---|---|
registration.created | Successful POST /agent/identity | registration_id, registration_type, iss, sub |
registration.interaction_required | 401 interaction_required | registration_id, iss, sub, matched_user_id |
registration.login_required | 401 login_required | iss, sub, auth_time, max_age |
claim.initiated | /agent/identity/claim called | registration_id, email |
claim.completed | User submitted correct user_code | registration_id, claimed_by_user_id |
claim.expired | user_code window or registration expired | registration_id |
token.exchanged | /oauth2/token jwt-bearer success | registration_id, access_token_id |
token.revoked | /oauth2/revoke called | access_token_id |
registration.revoked | SET processed at events_endpoint | registration_id, iss, sub |
auth_time is required in ID-JAGs. Service validates against idJagMaxAuthAgeSeconds. If too old, returns login_required (401) — agent must get user to re-authenticate at provider.claim_token is a bearer secret. Store only SHA-256 hash server-side.resource_name and resource_logo_uri from PRM to the user before asserting identity. This is the user's only consent gate./oauth2/revoke, kills one access_token) vs registration layer (provider-driven SETs at events_endpoint, tears down the whole delegation: identity_assertion + derived tokens + registration + claim handle — not tokens alone; see sample #21).jti values with TTL of at least exp - iat + clock skew (typically 6 min).client_id is a URL, fetch as Client ID Metadata Document and verify jwks_uri.| Code | Where | Meaning |
|---|---|---|
anonymous_not_enabled | /agent/identity | Service doesn't accept anonymous |
service_auth_not_enabled | /agent/identity | service_auth disabled |
issuer_not_enabled | /agent/identity | Provider not on trust list |
invalid_request | /agent/identity | Body/claim/signature/jti/aud problems |
interaction_required (401) | /agent/identity | ID-JAG matched account, no delegation — claim needed |
login_required (401) | /agent/identity | auth_time too old — re-authenticate at provider |
invalid_claim_token | /agent/identity/claim | Token wrong or expired |
claimed_or_in_flight | /agent/identity/claim | Already claimed or wrong endpoint |
claim_expired | /agent/identity/claim | Registration expired |
invalid_grant | /oauth2/token | Assertion expired/revoked |
invalid_client | /oauth2/token | client_id not recognized |
unsupported_grant_type | /oauth2/token | Not jwt-bearer or claim grant |
authorization_pending | /oauth2/token (claim) | User hasn't completed ceremony |
expired_token | /oauth2/token (claim) | user_code window closed |
slow_down | /oauth2/token (claim) | Polling too fast |
rate_limited (429) | any | Back off and retry |
The isitagentready.com scanner validates auth.md as the authMd check. Pass criteria:
/auth.md served from site root with HTTP 200/.well-known/oauth-protected-resource/.well-known/oauth-authorization-serverTo pass the check minimally:
# auth.md
This service accepts AI agent registrations.
## Authentication
Agents can register via POST /agent/identity with a valid ID-JAG.
See below for supported methods.To pass with full marks (all metadata):
/auth.md with proper heading/.well-known/oauth-protected-resource with resource, resource_name, resource_logo_uri, authorization_servers, scopes_supported, bearer_methods_supported: ["header"]/.well-known/oauth-authorization-server with issuer, token_endpoint, revocation_endpoint, grant_types_supported, and agent_auth block containing skill, identity_endpoint, claim_endpoint, events_endpoint, and registration methodsScan command:
curl -s -X POST 'https://isitagentready.com/api/scan' \
-H 'Content-Type: application/json' \
-d '{"url":"https://YOUR-DOMAIN/","enabledChecks":["authMd"]}' | jq '.checks.discovery.authMd'Before delivering output, verify:
auth.md contains all required steps (1-6) + Errors + Revocationissuer, token_endpoint, revocation_endpoint, grant_types_supportedagent_auth block includes identity_endpoint, claim_endpoint, events_endpointidentity_types_supported matches the flows the user chosescopes_supported reflects actual API scopes found in codebase/oauth2/token with jwt-bearer grant{{...}}, <your-...>, [YOUR_...])auth_time documentedreferences/protocol-template.md — Complete auth.md template with all sections and placeholdersreferences/validation-rules.md — Full validation ruleset with error messages and severitiesreferences/metadata-schema.md — JSON schema for PRM, AS metadata, ID-JAG, and identity_assertionreferences/example-auth-md.md — Working example of a complete auth.md file (Acme Notes)references/implementation-guide.md — Server-side implementation guide with token exchange, claim ceremony, revocation, and securityThis skill ships with a snapshot of the auth.md protocol specification (v2, June 2026). When possible, fetch the latest version from:
https://auth-md.comhttps://raw.githubusercontent.com/workos/auth.md/refs/heads/main/AUTH.mdhttps://workos.com/auth-md/docshttps://workos.com/auth-md/docs/appshttps://workos.com/auth-md/docs/agent-providershttps://workos.com/auth-md/docs/auth-mdIf fetch fails, use the bundled references/ as the source of truth.
© fabricioctelles, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in skills/auth-md of fabricioctelles/skills.
Open the folder on GitHubat commit f1de632
Auth Md next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auth Md this skillfabricioctelles/skills | 106 | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| OmniRoute Provider Managementdiegosouzapw/OmniRoute | 75k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Antipattern Preventiondoorkeeper-gem/doorkeeper | 5.5k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Cognitoitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Notion Worker Third-Party Auth Guidemakenotion/workers-template | 439 | 1 repos | ~3.5k | Automated safety check: Notes | MIT |
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
diegosouzapw/OmniRoute
Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.
doorkeeper-gem/doorkeeper
Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
makenotion/workers-template
Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.
kanchengw/cnllm
Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…
fabricioctelles/skills
Produce a short motion-graphics video ad — a 15s Facebook/Instagram/TikTok spot — as a rendered MP4.
fabricioctelles/skills
Audit, score, and compare repositories containing portable Agent Plugins against the official Agent Plugins specification.
fabricioctelles/skills
Design well-structured agent loops with best-practice coaching and cross-model review gates before you run them.
fabricioctelles/skills
This skill should be used when the user needs to consume the Pier Cloud (Lighthouse) API for cloud cost management — including JWT authentication, listing contexts, workspaces, workspace groups, and…
fabricioctelles/skills
Automated iterative agent runner for spec-based development in Kiro.
fabricioctelles/skills
Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.
Categories
Generate, validate, and explain auth.md files — the open protocol for AI agent registration. Auth Md is an agent skill from fabricioctelles/skills.md files — the open protocol for AI agent registration.
Auth Md fits situations like: making apps agent-ready; generating Protected Resource Metadata (RFC 9728); validating auth.md files; implementing agent registration endpoints.
Run `npx skills add fabricioctelles/skills --skill auth-md -a claude-code`. Or copy the skill folder (skills/auth-md in fabricioctelles/skills) into .claude/skills/auth-md in your project. Claude Code loads it when a task matches its description.
Run `npx skills add fabricioctelles/skills --skill auth-md -a codex`. Or copy the skill folder (skills/auth-md in fabricioctelles/skills) into .agents/skills/auth-md in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fabricioctelles/skills --skill auth-md -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth-md, .gemini/skills/auth-md, .github/skills/auth-md and .opencode/skills/auth-md in your project.
Going by SKILL.md and its folder, Auth Md needs the command-line tools its instructions call (curl and jq).
SKILL.md names 5 domains. In commands or code: workos.com, isitagentready.com, service.com, auth-md.com and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Auth Md is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Auth Md: Fortify Development (coollabsio/coolify, 63k stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 75k stars), Antipattern Prevention (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
fabricioctelles (a GitHub user) maintains it in fabricioctelles/skills, which has 106 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 4, 2026.
Source: fabricioctelles/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.