# Agent ID quickstart

Use this workflow when a coding Agent is asked to connect a website to Agent ID.

1. Read https://xagent.id/auth.md and follow its ownership and credential boundaries.
2. Read https://xagent.id/skill.md for supported workflows and evidence rules.
3. Ask the website owner for the exact HTTPS URL they control. Confirm the hostname is the intended customer domain before calling https://xagent.id/api/site_agents/install_guide?url=<customer-url>.
4. Verify domain ownership through the returned DNS, .well-known, or HTML challenge before requesting credentials or creating an installation plan.
5. Run the production preflight and installer in dry-run mode.
6. Present the exact `site_url`, detected framework, bounded opportunity report, `verified`, `content_validated`, `symlink_policy`, proposed managed files, excluded side effects, and verification steps to the owner.
7. Stop and obtain explicit human approval before any file write, domain proof, secret creation, deployment, or production action.
8. After approval, apply only the generated Agent ID managed files and verify the public proof URL and its returned agent identity.

The local opportunity report checks only whether a fixed list of public integration paths exists. `present` means only that a non-symlink path was accessible; `verified: 0` and `content_validated: false` mean that contents, signatures, domain ownership, and public reachability are not proven. The installer does not upload customer source, read secret files, modify customer content, deploy the website, or create credentials during dry-run. Agent ID does not guarantee ranking, AI citation, recommendation, conversion, or business lift.
