Cross-Domain Auth API Reference — RETIRED
⛔ RETIRED (2026-06-25). The API this page documented no longer exists. The oracle-bridge one-time-token cross-domain flow —
POST /api/auth/cross-domain-token(mint),POST /api/auth/exchange-token(consume), and thefounderyos-apireceiverPOST /api/v1/auth/cross-domain-login— was deleted on 2026-06-25 (oracle-bridge478b50a,0 937 src/routes/cross-domain-auth.ts, dac-001-5 Phase 6, PR oracle-bridge#332). All three endpoints now return404. Thefounderyos-apireceiving service was itself retired and its repository deleted on 2026-07-16 (bl-1073), not archived.Cross-domain SSO moved to identity-service PKCE. See What replaced it below. This page is kept only as a redirect + historical record; do not implement against anything described here. (bl-1286)
Status: Retired 2026-06-25 · superseded by identity-service (ADR-024 / ADR-025 / ADR-026) Former services: oracle-bridge (mint + exchange, routes deleted) · founderyos-api (receiver, repo deleted bl-1073) · @hello-world-co-op/auth (frontend helper) Former epic: PLATFORM-003 (cross-product auth delegation, 2026-04-20) — the mechanism it delivered has since been replaced
What replaced it
Cross-domain single-sign-on between helloworlddao.com and founderyos.dev is now served by identity-service, the canonical auth authority (ADR-024), using a PKCE-style one-time-code handoff instead of the oracle-bridge shared-service-token exchange:
| Method | Service | Path | Purpose |
|---|---|---|---|
POST | identity-service | /cross-domain/authorize | Mint a single-use cross-domain handoff code from an authenticated session |
POST | identity-service | /token/exchange | Consume the handoff code and return a fresh ES256 JWT |
Both endpoints are live and wired in identity-service's router (src/lib.rs, cross_domain_authorize_handler + token_exchange_handler). The JWT is KMS-signed ES256, JWKS-verifiable, and already carries ic_principal and roles.
Edge integration (ADR-025 disposition, Coby 2026-06-18): the FounderyOS dashboard calls relative same-origin /api/v1/auth/*; the founderyos.dev edge ingress proxies those to identity-service and rewrites the Set-Cookie domain to the dashboard origin so the refresh cookie lands first-party. There is no browser-visible cross-domain XHR and no shared service token in the member SSO path.
⚠️
CROSS_DOMAIN_SERVICE_TOKENis NOT the replacement. It was a server-to-server service-trust secret, never a member-SSO mechanism; it survived478b50adeliberately and has since been ruled retired (bl-1272). Do not point cross-domain SSO work at it.
Authoritative sources for the current model
- ADR-024 — identity-service as the auth source of truth
- ADR-025 — FOS member edge auth (identity JWT); the same-origin proxy disposition
bmad-artifacts/adrs/ADR-026-dao-auth-consolidation.md— DAO auth consolidation; P5 collapses the cross-domain handoff onto/token/exchange- identity-service source (
src/lib.rs,src/session_handlers.rs) — the live route definitions
Historical record (PLATFORM-003, 2026-04-20 → retired 2026-06-25)
For history only, the retired flow worked as follows: a browser minted a 30-second single-use token at oracle-bridge (/api/auth/cross-domain-token, session cookie + CSRF), was redirected to founderyos.dev/auth/cross-domain-login?token=…, the FOS frontend posted the token to founderyos-api (/api/v1/auth/cross-domain-login), which exchanged it server-to-server with oracle-bridge (/api/auth/exchange-token, Authorization: Bearer CROSS_DOMAIN_SERVICE_TOKEN) for a 9-field user profile and minted its own session cookies. The token was SHA-256-at-rest, session-bound (ON DELETE CASCADE), audience-checked, and single-use via UPDATE … WHERE used_at IS NULL RETURNING *. The full pre-retirement text of this page is recoverable from git history (git log --follow api/cross-domain-auth.md).
Why it was replaced: auth consolidated onto identity-service (ADR-024 → ADR-026) so that one IdP issues JWTs for every product, rather than each product minting its own session from an oracle-bridge token exchange.
Related documentation
- System Topology → Cross-domain auth bridge — topology view, carries the same superseded note
- ADR-024 / ADR-025 / ADR-026 — the current auth model
- Auth package —
@hello-world-co-op/auth
Maintainer: Platform Team Retired: 2026-06-25 (bl-1286)