Sign in with Denpa
A fork does not need its own account system. Users click Sign in with Denpa, approve the scopes your app asks for on denpa.ai, and your app receives their permanent Denpa ID, a scoped bearer token, and access to the public Passport (username, avatar, stats, station identities).
app → POST /api/protocol/v1/auth/challenge → user visits https://denpa.ai/authorize?challenge=… (approves scopes) → redirect_uri?code=…&state=… → POST /api/protocol/v1/auth/token (PKCE verifier or client secret) → Authorization: Bearer dat_… on /api/protocol/v1/*Add the button
Section titled “Add the button”import { Denpa } from "@denpa/sdk/protocol";
const denpa = new Denpa({ clientId: "dapp_yourapp", // registered at the hub redirectUri: "https://yourapp.example/auth/denpa/callback", scopes: ["profile:read", "signal:read", "signal:create"],});
// the buttonawait denpa.auth.signIn();
// on the callback pageconst session = await denpa.auth.handleCallback(); // state + PKCE verifiedconst me = await denpa.users.me(); // Passport + granted scopesawait denpa.signals.create({ marketId: "540818", position: "YES" });No SDK? The whole flow is ~80 lines of fetch — see examples/siwd-demo.
Scopes
Section titled “Scopes”Three tiers, never conflated: authentication (profile:read),
authorization (station:*, broadcast:*, event:read, signal:*,
prediction:*, market:*, resolution:read, signer:manage) and
financial (wallet:*) — the last is refused by Sign in with Denpa and
needs its own explicit step. Users revoke any app at /user → APPS.
Registration
Section titled “Registration”Self-serve: sign in at denpa.ai/developer → YOUR APPS → REGISTER.
Choose a slug (→ dapp_<slug>), redirect URIs, browser origins, and the scopes your
app may request; tick confidential only for server apps (mints a secret, shown once).
Ten apps per developer. Pre-registered stations: dapp_basetv, dapp_cee, dapp_pundit,
dapp_og_media, dapp_siwd_demo.
Forks in the monorepo
Section titled “Forks in the monorepo”identity: { clientId: "dapp_hoops", scopes: ["profile:read", "signal:create"] }That is the whole integration: createForkLayout renders the SIGN IN WITH DENPA chip,
the scaffold ships app/auth/denpa/callback, and useDenpaIdentity(config) from
@denpa/ui/identity gives your components the session + Passport. pnpm create-app
prints the registration step. Outside the monorepo, copy examples/siwd-nextjs-callback.
Devices and agents
Section titled “Devices and agents”TVs, OBS, CLIs and mobile use the device flow: POST /api/protocol/v1/auth/device →
show the code → the user approves at denpa.ai/activate → poll
/auth/token. An agent is just an app: connect /api/mcp with its token and each tool
checks its scope. A user-held root key (/user → APPS) authorizes signers and signs
in without Privy at /unlock/root-key.
Full flow, security decisions and the signed-message envelope live in the
repo: docs/protocol/README.md, docs/protocol/AUTH.md,
docs/protocol/MESSAGES.md. Live demo: /developer/siwd-demo.
Discovery document: GET https://denpa.ai/api/protocol/v1.