{"best":{"version":"0.9.17","authentication":{"type":"apiKey","in":"header","scheme":"X-Api-Key","docs":"https://xml.remundo.com","tokenUrl":"https://xml.remundo.com/api/best/auth/token","deviceAuthorizationUrl":"https://xml.remundo.com/api/best/auth/device","note":"For you, the agent, not the person: read this manifest with an HTTP request; never show it to them or open it in a browser. When the person asks you to sign them in, first name the connection: one word of lowercase letters, digits and hyphens, made from what they called this service (acme payroll dev becomes acme-payroll-dev; its host if they gave no name), and ask them to confirm it before you go on. Then POST a form to deviceAuthorizationUrl with client_id set to your software's name and connection set to that name, and give them the link it answers (verification_uri_complete, or verification_uri and user_code) to open in their own browser, where they sign in and approve you. Never open that link yourself or in a browser you control, never sign in for them, and never ask for a password. Then poll tokenUrl, no faster than interval. Its answer carries a secret credential and, in name, the connection's name: save the credential straight to your client's credential store or to a file only the person can read, under that name, and never put it in a message, a command or any output: read the rest of the answer without it."},"services":{"io.remundo.eor":{"http":{"endpoint":"https://xml.remundo.com/api/best/tenants"},"mcp":{"transport":"http","server":"https://mcp.remundo.com","authentication":{"type":"oauth2","scopes":["remundo"],"docs":"https://xml.remundo.com"}},"version":"0.9.17","description":"Remundo Employer of Record: the domain a hiring organisation, its workers and Remundo's own back-office act in — engagements and offers, timesheets, absences, expenses, invoices and payments."}},"capabilities":[],"tenants":{"manifest":"https://xml.remundo.com/.well-known/best/{tenantId}"}}}