«Sign in with Prizrak» for any website. People sign in with their Prizrak address and confirm it in the app — no passwords in the browser. Standard OpenID Connect: ready-made plugins for WordPress, Nextcloud, forums and more work out of the box.
prizrak.im — one for the whole federation: people from any Prizrak server sign in through it, and it asks their home server to confirm. Websites only need to know one address — https://prizrak.im.The website opens the Prizrak sign-in page. It shows the website’s name, its domain and whose it is.
Type your Prizrak address, for example fox:prizrak.im or vasya:ru.prizrak.im. Or open Prizrak on your phone — + → «Scan QR code» — and point it at the code on the page.
A request appears on all your devices: which website, which domain, what it will learn. The page shows a number — tap the same number in the app. The request lives for 2 minutes.
The website receives your address (and your name and avatar — only if you allowed it). Your Prizrak password is never typed in a browser and never reaches the website.
The website talks to one sign-in server. Your identity is confirmed by your own home server and your own devices — over the signed Prizrak federation.
Sends the person to prizrak.im/oauth/authorize (OpenID Connect, code + PKCE).
Sign-in server. Finds the person’s home server by the address and asks it — with a request signed by the server key.
Any Prizrak server. Checks the account exists and sign-in is allowed, forwards the request to the person’s devices.
You tap the number from the page. The home server signs the answer and sends it back to prizrak.im.
id_token is signed by prizrak.im (RS256 or ES256), sub is the full Prizrak address, and home_assertion carries the home server’s own signature — so the answer can be checked all the way to the person’s server.Discovery, JWKS, authorization code, PKCE, refresh tokens, userinfo, revocation. Any OIDC plugin or library works — no custom code.
One issuer — https://prizrak.im. Users of every Prizrak server sign in through it; websites don’t have to know about each server.
Sign-in is confirmed in the app. Nothing to phish on a fake page: there is no password field at all.
Three numbers in the app, one on the page — accidental «Allow» on a flood of requests won’t work. Or scan the QR code on the page.
Name and avatar are given only with a checkmark. «Websites you signed in to» — with revocation; sign-in can be switched off entirely.
Any Prizrak user registers a website in the app and gets client_id and a secret immediately — no approval, no forms.
Desktop or Android: Settings → Privacy → «Sign in to websites with Prizrak» → «My websites» → «Register a website». Enter the name, the domain (forum.example.com) and the redirect URI your plugin shows (https://forum.example.com/…/callback).
The secret is shown once — save it right away (a new one can be issued at any time; the old one stops working). The app also shows ready-made settings for the plugin.
Most plugins only need the discovery address, client_id and the secret — they read everything else themselves.
| Setting | Value |
|---|---|
| Issuer | https://prizrak.im |
| Discovery | https://prizrak.im/.well-known/openid-configuration |
| Client ID / Secret | From the app — «My websites». |
| Scopes | openid (address), profile (name and avatar, if the person allows), offline_access (refresh token). |
| Redirect URI | Exactly as registered. Only https:// on your domain or its subdomains; http://localhost — for testing. |
| PKCE | S256. Required for websites/apps without a secret, recommended for everyone. |
| Client authentication | client_secret_basic, client_secret_post, none (+PKCE) |
| Username / ID | Identify people by sub (the full address, e.g. vasya:ru.prizrak.im). For a login name use preferred_username — some platforms do not allow «:» in names. |
| Endpoint | Description |
|---|---|
/.well-known/openid-configuration | Discovery — everything a plugin needs. |
/oauth/authorize | Sign-in page: response_type=code, client_id, redirect_uri, scope, state, nonce, code_challenge. |
/oauth/token | Code → tokens (authorization_code, refresh_token). The code lives 60 s and works once; access token — 1 hour. |
/oauth/userinfo | Who signed in (Bearer access token). |
/oauth/jwks | Public keys for checking id_token (RS256 and ES256). |
/oauth/revoke, /oauth/end_session | Revoke a token; sign out and return to post_logout_redirect_uri. |
| Claim | Description |
|---|---|
sub, prizrak_id | The full Prizrak address: name:server. Stable, unique across the federation. |
preferred_username | The name part of the address (vasya). |
name, picture | Display name and avatar — only if the person allowed it (scope profile). |
home_assertion | The answer of the person’s home server, signed by its federation key (Ed25519, /.well-known/prizrak/server). Optional to check. |
nonce, auth_time, at_hash | Standard OpenID Connect claims. |
# 1. Send the person to the sign-in page
https://prizrak.im/oauth/authorize?response_type=code&client_id=pz_XXXX
&redirect_uri=https%3A%2F%2Fforum.example.com%2Fcallback
&scope=openid%20profile&state=RANDOM&nonce=RANDOM
&code_challenge=BASE64URL(SHA256(verifier))&code_challenge_method=S256
# 2. They come back with ?code=…&state=… — exchange the code for tokens
curl -u pz_XXXX:SECRET https://prizrak.im/oauth/token \
-d grant_type=authorization_code -d code=CODE \
-d redirect_uri=https://forum.example.com/callback -d code_verifier=VERIFIER
# {"access_token":"…","id_token":"eyJ…","token_type":"Bearer","expires_in":3600}
# 3. Who is it
curl -H "Authorization: Bearer ACCESS_TOKEN" https://prizrak.im/oauth/userinfo
# {"sub":"vasya:ru.prizrak.im","preferred_username":"vasya","name":"Vasya"}
Official Prizrak plugins will be published right here. Until then, the standard OpenID Connect plugins of popular platforms already work — just give them the discovery address, client_id and the secret.
Plugin «OpenID Connect Generic Client». Login type — button, identity key — sub, nickname — preferred_username.
App «OpenID Connect user backend» (user_oidc): add a provider with the discovery address; unique user ID — sub.
Built-in OpenID Connect plugin: enable it, paste the discovery address, client_id and the secret.
Site administration → Authentication sources → OAuth2 → provider «OpenID Connect», auto-discovery URL.
Works nowSection [auth.generic_oauth]: the authorize, token and userinfo addresses from the table above, scopes openid profile.
A «Sign in with Prizrak» button with the ghost, one-click setup for WordPress and other platforms, notifications from the website to Prizrak. They will be published on this page.
Coming soonA website learns your address (and name/avatar if allowed). Your chats, contacts and files are end-to-end encrypted and are never given to websites — OAuth doesn’t touch them.
prizrak.im accepts an answer only if it is signed by the server from your address: ru.prizrak.im can confirm only *:ru.prizrak.im.
The confirmation window always shows the real domain and the owner of the website. The prizrak.im administrator can block a fraudulent website — its sign-in stops working and its tokens are revoked.
A request lives 2 minutes, the code — 60 seconds and works once, access tokens — an hour; refresh tokens rotate on every use and can be revoked from the app.
Your server doesn’t have to become an OAuth server: prizrak.im handles sign-in for the whole federation and asks your server to confirm. What’s needed is a Prizrak server 2.1.68 or newer and the app 2.1.132 (desktop) / 2.1.169 (Android) or newer. Websites registered from any server — through prizrak.im.
"oauthProvider": true in the server config — and your own issuer, https://your-domain. Other servers of that network point to it with "oauthProviderDomain": "your-domain". For the public federation this is not needed.Register the website in the app, paste three values into the plugin — and people from the whole federation can sign in without passwords.