Nothing gets a token without the seal.
Signet stands between your users and your services: it authenticates people, asks their consent, and stamps every token your platform runs on — then remembers who holds what.
issuer signet.wu-boy.com alg RS256 flows device / auth-code+PKCE / refresh / client-credentials
Where every request passes through
authorization code · pkce · device grantYour app
CLI, web, mobile, or service — asks for access
Signet
Authenticates, asks consent, stamps the token
Your API
Verifies the signature against the public JWKS
Strict on the way in, generous on the way out
Standards-compliant flows for every kind of client, and full visibility once a token exists.
Device flow for CLIs
Terminals, SSH sessions, and CI runners sign in with a short code — no secret in the binary.
RFC 8628Auth code + PKCE
Web and mobile apps authorize without a client secret; redirect URIs are exact-matched.
RFC 6749 · 7636Rotating refresh tokens
One-time-use refresh tokens with family tracking — a replayed token revokes its line.
RFC 6749 §6Consent, per app
Each app receives exactly the scopes you approved. Review and withdraw grants anytime.
SCOPESA full audit trail
Every login, grant, and revocation recorded and exportable, sensitive fields masked.
AUDITBring your identity
GitHub, GitLab, Gitea, Microsoft Entra ID — or your own HTTP API behind the login form.
OAUTH LOGINYour platform. Your seal.
Sign in to manage your devices, connected apps, and grants — or point an OAuth library at the issuer and start integrating.
/oauth/device/code · /oauth/authorize · /oauth/token · /oauth/revoke