Skip to main content

kb-fediverse-openwebauth

Stars8
Forks0
UpdatedMarch 13, 2026 at 02:41

Background knowledge about the OpenWebAuth (OWA) federated remote authentication protocol, based on FEP-61cf (DRAFT status). Covers the 5-step authentication handshake between home instance, target instance, and user browser; WebFinger discovery of redirect and token endpoints (rel="http://purl.org/openwebauth/v1" and v1#redirect); HTTP Signature signed token requests; RSA PKCS#1 v1.5 encrypted single-use tokens; the owt query parameter; the zid login trigger; the /magic fallback endpoint; authentication vs authorization distinction; security considerations (open redirects, CSRF, information leakage, token expiry); the history from Magic Auth in Mistpark (2010) through Zot and Hubzilla to standalone OpenWebAuth (2017); comparison with OAuth 2.0 and OIDC (FEP-d8c2); use cases for private content access, cross-server permissions, and wall-to-wall posting; and implementations across Hubzilla, Streams, Forte, Friendica, and FedIAM. Load when the user asks about federated single sign-on in the Fediverse; OpenWebAu

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly