From 43151959b32152029dccf97a2331ed8f836858bc Mon Sep 17 00:00:00 2001 From: Anthony Ettinger Date: Sat, 12 Sep 2026 18:59:43 +0000 Subject: [PATCH] Serve an OpenAccess descriptor at /.well-known/openaccess.json Lists DiskPush on OpenAccess hubs (openaccess.logicsrc.com) so people can link it with OAuth 2.1 + PKCE and it honours the shared profullstack.com/all-access entitlement. The Ed25519 public key here is the app's credential for reporting sales; the private half is in the logicsrc teams vault openaccess-app-keys--prod. Scopes are empty for now: the reserved openid, email and entitlements scopes need no listing. Spec: https://logicsrc.com/openaccess Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01SWRffW4ifQPUrGXJtgYWMd --- apps/web/public/.well-known/openaccess.json | 29 +++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 apps/web/public/.well-known/openaccess.json diff --git a/apps/web/public/.well-known/openaccess.json b/apps/web/public/.well-known/openaccess.json new file mode 100644 index 0000000..107bb75 --- /dev/null +++ b/apps/web/public/.well-known/openaccess.json @@ -0,0 +1,29 @@ +{ + "openaccess": "0.1", + "name": "DiskPush", + "url": "https://diskpush.com", + "operator": "https://logicsrc.com/.well-known/openprofile.md", + "redirect_uris": [ + "https://diskpush.com/api/v1/openaccess/callback" + ], + "jwks": { + "keys": [ + { + "kty": "OKP", + "crv": "Ed25519", + "kid": "rRqaGaxjcvzo", + "x": "JGLFXXHksqT-m6ZfreoexAw-TNd6TzlVCDgmMb6CHik", + "alg": "EdDSA", + "use": "sig" + } + ] + }, + "scopes": {}, + "honours": [ + "profullstack.com/all-access" + ], + "webhooks": "https://diskpush.com/api/v1/openaccess/events", + "hubs": [ + "https://openaccess.logicsrc.com" + ] +}