AROYN SCRIPT HUB / WEB DASHBOARD

Authentication flow

Separate browser sign-in, dashboard keys and scoped live authorization.

Browser sign-in#

The dashboard sends the browser to the API’s Discord sign-in flow. Discord returns to /api/v2/auth/discord/callback. The frontend receives a temporary exchange code and exchanges it for an Aroyn browser session; it removes the exchange parameter from the URL before storing the session.

The current auth-service.js uses /api/v2/auth/discord/start, /api/v2/auth/exchange and /api/v2/auth/me for start, exchange and session validation. These paths explain the implemented flow; they are not a complete supported third-party API contract.

Runtime credentials#

CredentialPurpose
Browser sessionAccess your authenticated dashboard/account actions.
Dashboard keyLink the Hub runtime to that Aroyn account. Treat it like a password.
Live authorizationAuthorize the live transport for its runtime/dashboard role.
Presence tokenScope basic-presence updates and disconnect; it cannot read detailed account telemetry.

For presence WebSockets, credentials are sent in TLS-protected frames rather than URL query parameters. The session identifier used in the presence route is not a secret credential.

Domain and session boundaries#

The custom domain’s redirect returns to the requested dashboard/admin route while using the existing API callback. Browser storage on the Pages origin is separate from storage on aroyn.xyz. A first login on the new origin is expected; use the same Discord identity.

Revocation and account deletion#

Account deletion revokes Aroyn sessions and keys. Deletion also requires a recent Discord sign-in and exact confirmation. See account data for pending cleanup and retention limits.