Authentication
Host-authorized device pairing and operator credential lifecycle.
📄️ List owner-controlled plugin grants
List explicit paired-device plugin privileges from the direct localhost or verified Tailscale dashboard. This route is unavailable through relay access and refuses any paired bearer, including on the direct listener. It does not expose credentials. Existing pairings have no plugin grants.
📄️ Replace one device's explicit plugin grants
Replace plugin read, management and approval grants after a direct owner dashboard check and expected-revision comparison. An empty scope list revokes every plugin grant immediately, including for existing access tokens. A presented paired bearer is refused even with matching direct-owner origin headers. Remote operators cannot call this route or grant themselves privileges.
📄️ List dashboard pairing invitations
Return safe invitation status without bearer nonces or pairing codes. This management route is available only to the configured gateway dashboard over localhost or Tailscale and never through the relay gateway.
📄️ Create a dashboard pairing invitation
Create one bounded, revocable pairing invitation from the configured gateway dashboard over localhost or Tailscale. The secret pairing code is returned once with no-store response headers and is never relay-accessible.
📄️ Revoke a dashboard pairing invitation
Immediately prevent new and unfinished pairing attempts for one invitation without revoking devices that already paired. This management route is available only to the configured gateway dashboard over localhost or Tailscale and is never relay-accessible.
📄️ Bind a device key to a local pairing session
Accept a candidate Ed25519 public key only when the nonce names an unexpired host-created pairing session or invitation, then return one random challenge for proof of possession. Reusable invitations return an independent five-minute attempt identity.
📄️ Exchange a device-key proof for operator credentials
Verify the candidate device's Ed25519 signature, consume its single-use session or independent invitation attempt, and return short-lived access plus rotating refresh credentials exactly once.
📄️ Rotate an operator refresh credential
Accept the current opaque refresh credential for one paired device, invalidate its existing token pair, and return a fresh short-lived access token plus rotating refresh token exactly once.
📄️ List paired operator devices
Return safe active and revoked device projections for a bearer credential with device-management scope or a verified direct dashboard. Credential material is never included.
📄️ Revoke a paired operator device
Immediately invalidate the target device's access and refresh credentials. Repeating revocation for an already revoked device is idempotent. Requires device-management bearer scope or verified direct dashboard authority.