# Nettipoika Sivusto agent discovery Environment: prod Release: rel-20261008-r4 Source commit: a3e1a73b8b8dd3873017331b9f3f5d9747d5905a HTTP API: v1 Payment API: 0.25.0 MCP protocol: 2026-07-28 Canonical URL: https://sivusto.nettipoika.fi/llms.txt Product discovery index: https://nettipoika.fi/llms.txt Nettipoika lets a customer-owned agent operate the websites a person authorizes through a deterministic HTTP API or its thin MCP adapter. One subscription includes any number of websites inside the account's shared CPU, memory and storage pool. Discovery never grants authority. A human authorizes identity, terms, recurring payment, sensitive scopes, account recovery, destructive database actions and final deletion. Start with https://sivusto.nettipoika.fi/agents/v1/getting-started.md. - Operational OpenAPI: https://sivusto.nettipoika.fi/openapi.json - Human enrollment and account OpenAPI: https://sivusto.nettipoika.fi/payment/openapi.json - Executable capabilities: https://sivusto.nettipoika.fi/api/v1/capabilities - Retry and operation rules: https://sivusto.nettipoika.fi/agents/v1/operations.md - Capability boundaries: https://sivusto.nettipoika.fi/agents/v1/capabilities.md - OAuth client setup and approved scopes: https://sivusto.nettipoika.fi/agents/v1/oauth-setup.md - MCP endpoint: https://sivusto.nettipoika.fi/mcp - OAuth protected-resource metadata: https://sivusto.nettipoika.fi/.well-known/oauth-protected-resource/mcp An authorization is bound to one site, or with the person's explicit approval to every website of their account, plus explicit scopes and a revocable connection. With access to several websites, name the `site_id` the person means on every call and ask the person when they have not said which website; never guess. If site selection is skipped or unanswered, wait for an explicit website before editing. Deleting a website always needs the owner's confirmation on the dashboard. Access tokens expire in at most 15 minutes; a conforming OAuth client renews them with the advertised metadata and its protected rotating refresh credential. Never put credentials or verifiers in a URL, source file, prompt, log or version control. Every HTTP mutation requires an `Idempotency-Key`; poll returned operation resources until a terminal state. Customer sites use hostnames returned by the authenticated site API under the configured `nettipoika.fi` suffix. Do not infer a site hostname from this product origin or from an incoming Host header.