Skip to main content

kb-fediverse-openwebauth

스타8
포크0
업데이트2026년 3월 13일 02:41

Background knowledge about the OpenWebAuth (OWA) federated remote authentication protocol, based on FEP-61cf (DRAFT status). Covers the 5-step authentication handshake between home instance, target instance, and user browser; WebFinger discovery of redirect and token endpoints (rel="http://purl.org/openwebauth/v1" and v1#redirect); HTTP Signature signed token requests; RSA PKCS#1 v1.5 encrypted single-use tokens; the owt query parameter; the zid login trigger; the /magic fallback endpoint; authentication vs authorization distinction; security considerations (open redirects, CSRF, information leakage, token expiry); the history from Magic Auth in Mistpark (2010) through Zot and Hubzilla to standalone OpenWebAuth (2017); comparison with OAuth 2.0 and OIDC (FEP-d8c2); use cases for private content access, cross-server permissions, and wall-to-wall posting; and implementations across Hubzilla, Streams, Forte, Friendica, and FedIAM. Load when the user asks about federated single sign-on in the Fediverse; OpenWebAu

설치

Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.

SKILL.md
readonly