# BanditPOS > Point-of-sale, inventory, and purchasing system for Bandit Machine, with QuickBooks Desktop synchronisation. BanditPOS is a private, single-tenant application operated by Bandit Machine. It is not a public website and it has no public content to read: the sign-in page is the only page an unauthenticated client can render. Every other route requires a session cookie and answers 401, or redirects to /login for a browser navigation. There is no *public* API: nothing here is readable without a credential, and every credential acts as a named staff account. An agent can obtain one of its own: register at https://pos.banditmachine.com/oauth/register, then send a member of staff through https://pos.banditmachine.com/oauth/authorize. They approve the scopes, and the token that comes back acts as them — within the scopes they chose, and never beyond their own permissions. There is no flow that skips that approval. See https://pos.banditmachine.com/auth.md before attempting any programmatic access. ## Documentation - [Authentication](https://pos.banditmachine.com/auth.md): how to obtain a token, and what it can reach. - [Full description](https://pos.banditmachine.com/llms-full.txt): the complete public description of this service. - [Agent skills](https://pos.banditmachine.com/.well-known/agent-skills/index.json): skills describing this service. - [API catalog](https://pos.banditmachine.com/.well-known/api-catalog): RFC 9727 catalog of the reachable endpoints. ## Public endpoints - [Sign in](https://pos.banditmachine.com/login): interactive sign-in, by password or Google. - [Health](https://pos.banditmachine.com/health): liveness probe, returns {"ok":true}. - [MCP endpoint](https://pos.banditmachine.com/mcp): Model Context Protocol over Streamable HTTP, revision 2026-07-28. 87 typed business tools, one per operation, each needing its own scope; the full list is in llms-full.txt and the banditpos-mcp-tools agent skill. ## Optional - [Authorization server metadata](https://pos.banditmachine.com/.well-known/oauth-authorization-server): RFC 8414 metadata for obtaining a token. - [Protected resource metadata](https://pos.banditmachine.com/.well-known/oauth-protected-resource): RFC 9728 metadata for this resource. - [Resource catalog](https://pos.banditmachine.com/.well-known/ai-catalog.json): Agentic Resource Discovery manifest.