Authentication flow
Separate browser sign-in, dashboard keys and scoped live authorization.
Browser sign-in#
The dashboard sends the browser to the API’s Discord sign-in flow. Discord returns to /api/v2/auth/discord/callback. The frontend receives a temporary exchange code and exchanges it for an Aroyn browser session; it removes the exchange parameter from the URL before storing the session.
The current auth-service.js uses /api/v2/auth/discord/start, /api/v2/auth/exchange and /api/v2/auth/me for start, exchange and session validation. These paths explain the implemented flow; they are not a complete supported third-party API contract.
Runtime credentials#
| Credential | Purpose |
|---|---|
| Browser session | Access your authenticated dashboard/account actions. |
| Dashboard key | Link the Hub runtime to that Aroyn account. Treat it like a password. |
| Live authorization | Authorize the live transport for its runtime/dashboard role. |
| Presence token | Scope basic-presence updates and disconnect; it cannot read detailed account telemetry. |
For presence WebSockets, credentials are sent in TLS-protected frames rather than URL query parameters. The session identifier used in the presence route is not a secret credential.
Domain and session boundaries#
The custom domain’s redirect returns to the requested dashboard/admin route while using the existing API callback. Browser storage on the Pages origin is separate from storage on aroyn.xyz. A first login on the new origin is expected; use the same Discord identity.
Revocation and account deletion#
Account deletion revokes Aroyn sessions and keys. Deletion also requires a recent Discord sign-in and exact confirmation. See account data for pending cleanup and retention limits.