OAuth 2.0 · OpenID Connect · Self-hosted

Nothing gets a token without the seal.

Signet stands between your users and your services: it authenticates people, asks their consent, and stamps every token your platform runs on — then remembers who holds what.

issuer signet.wu-boy.com alg RS256 flows device / auth-code+PKCE / refresh / client-credentials

Where every request passes through

authorization code · pkce · device grant
verify offline — /.well-known/jwks.json or introspect — POST /oauth/introspect revoke anytime — POST /oauth/revoke
What the gate enforces

Strict on the way in, generous on the way out

Standards-compliant flows for every kind of client, and full visibility once a token exists.

Device flow for CLIs

Terminals, SSH sessions, and CI runners sign in with a short code — no secret in the binary.

RFC 8628

Auth code + PKCE

Web and mobile apps authorize without a client secret; redirect URIs are exact-matched.

RFC 6749 · 7636

Rotating refresh tokens

One-time-use refresh tokens with family tracking — a replayed token revokes its line.

RFC 6749 §6

Consent, per app

Each app receives exactly the scopes you approved. Review and withdraw grants anytime.

SCOPES

A full audit trail

Every login, grant, and revocation recorded and exportable, sensitive fields masked.

AUDIT

Bring your identity

GitHub, GitLab, Gitea, Microsoft Entra ID — or your own HTTP API behind the login form.

OAUTH LOGIN
Self-hosted · single binary · SQLite or PostgreSQL

Your platform. Your seal.

Sign in to manage your devices, connected apps, and grants — or point an OAuth library at the issuer and start integrating.

/.well-known/openid-configuration · /.well-known/jwks.json
/oauth/device/code · /oauth/authorize · /oauth/token · /oauth/revoke