Skip to content

Sign in with Denpa

A fork does not need its own account system. Users click Sign in with Denpa, approve the scopes your app asks for on denpa.ai, and your app receives their permanent Denpa ID, a scoped bearer token, and access to the public Passport (username, avatar, stats, station identities).

app → POST /api/protocol/v1/auth/challenge
→ user visits https://denpa.ai/authorize?challenge=… (approves scopes)
→ redirect_uri?code=…&state=…
→ POST /api/protocol/v1/auth/token (PKCE verifier or client secret)
→ Authorization: Bearer dat_… on /api/protocol/v1/*
import { Denpa } from "@denpa/sdk/protocol";
const denpa = new Denpa({
clientId: "dapp_yourapp", // registered at the hub
redirectUri: "https://yourapp.example/auth/denpa/callback",
scopes: ["profile:read", "signal:read", "signal:create"],
});
// the button
await denpa.auth.signIn();
// on the callback page
const session = await denpa.auth.handleCallback(); // state + PKCE verified
const me = await denpa.users.me(); // Passport + granted scopes
await denpa.signals.create({ marketId: "540818", position: "YES" });

No SDK? The whole flow is ~80 lines of fetch — see examples/siwd-demo.

Three tiers, never conflated: authentication (profile:read), authorization (station:*, broadcast:*, event:read, signal:*, prediction:*, market:*, resolution:read, signer:manage) and financial (wallet:*) — the last is refused by Sign in with Denpa and needs its own explicit step. Users revoke any app at /user → APPS.

Self-serve: sign in at denpa.ai/developer → YOUR APPS → REGISTER. Choose a slug (→ dapp_<slug>), redirect URIs, browser origins, and the scopes your app may request; tick confidential only for server apps (mints a secret, shown once). Ten apps per developer. Pre-registered stations: dapp_basetv, dapp_cee, dapp_pundit, dapp_og_media, dapp_siwd_demo.

denpa.config.ts
identity: { clientId: "dapp_hoops", scopes: ["profile:read", "signal:create"] }

That is the whole integration: createForkLayout renders the SIGN IN WITH DENPA chip, the scaffold ships app/auth/denpa/callback, and useDenpaIdentity(config) from @denpa/ui/identity gives your components the session + Passport. pnpm create-app prints the registration step. Outside the monorepo, copy examples/siwd-nextjs-callback.

TVs, OBS, CLIs and mobile use the device flow: POST /api/protocol/v1/auth/device → show the code → the user approves at denpa.ai/activate → poll /auth/token. An agent is just an app: connect /api/mcp with its token and each tool checks its scope. A user-held root key (/user → APPS) authorizes signers and signs in without Privy at /unlock/root-key.

Full flow, security decisions and the signed-message envelope live in the repo: docs/protocol/README.md, docs/protocol/AUTH.md, docs/protocol/MESSAGES.md. Live demo: /developer/siwd-demo. Discovery document: GET https://denpa.ai/api/protocol/v1.