Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,8 @@ uses an OAuth2 authorization-code flow, refresh tokens, or a connector framework

| Surface | Prefix | Issues | Default `iss` | Published at |
|---------|--------|--------|---------------|--------------|
| [Sign-in](#siwe--address-control-tokens) | `/siwe` | Address-control token (`ethereum_address`) | `https://auth.dimo.zone` | `…/siwe/keys` |
| [Token exchange](#permissions--token-exchange) | `/permissions` | Permission token (`asset` / `permissions` / `cloud_events`) | `https://auth-roles-rights.dimo.zone` | `…/permissions/keys` |
| [Sign-in](#siwe--address-control-tokens) | `/siwe` | Address-control token (`ethereum_address`) | `https://dauth.dimo.zone/siwe` | `…/siwe/keys` |
| [Token exchange](#permissions--token-exchange) | `/permissions` | Permission token (`asset` / `permissions` / `cloud_events`) | `https://dauth.dimo.zone/permissions` | `…/permissions/keys` |

The exchange also exposes a gRPC `TokenExchangeService` on its own port. The two
surfaces share Go packages — `internal/keyset` (signing), `internal/oidc` (JWKS +
Expand Down Expand Up @@ -85,7 +85,7 @@ is stateless and offline-verifiable.
The chain is fixed by the `CHAIN_ID` config. Response:
```json
{
"challenge": "auth.dimo.zone wants you to sign in with your Ethereum account:\n0x6E4…A1b\n\nSign in to DIMO.\n\nURI: https://auth.dimo.zone\nVersion: 1\nChain ID: 137\nNonce: …\nIssued At: …\nExpiration Time: …",
"challenge": "dauth.dimo.zone wants you to sign in with your Ethereum account:\n0x6E4…A1b\n\nSign in to DIMO.\n\nURI: https://dauth.dimo.zone\nVersion: 1\nChain ID: 137\nNonce: …\nIssued At: …\nExpiration Time: …",
"nonce": "…",
"expires_at": "2026-06-14T17:25:00Z"
}
Expand Down Expand Up @@ -138,7 +138,7 @@ Point any validator at the issuer and JWKS. For example, `din`'s attestation
server is configured with:

```
TOKEN_EXCHANGE_ISSUER=https://auth.dimo.zone
TOKEN_EXCHANGE_ISSUER=https://dauth.dimo.zone/siwe
TOKEN_EXCHANGE_KEY_SET_URL=https://dauth.dimo.zone/siwe/keys
```

Expand All @@ -164,7 +164,7 @@ section); a few process-wide variables (`PUBLIC_BASE_URL`, `HTTP_ADDRESS`,
| Variable | Required | Default | Notes |
|----------|----------|---------|-------|
| `PUBLIC_BASE_URL` | yes | — | Externally reachable origin, e.g. `https://dauth.dimo.zone`. Base of each surface's `jwks_uri`; also the SIWE `uri` and default `SIWE_DOMAIN` host. |
| `SIWE_ISSUER` | yes | — | Absolute URL, e.g. `https://auth.dimo.zone`. The sign-in JWT `iss`. |
| `SIWE_ISSUER` | yes | — | Absolute URL, e.g. `https://dauth.dimo.zone/siwe`. The sign-in JWT `iss`. |
| `JWT_AUDIENCE` | yes | — | Comma-separated `aud` value(s). |
| `SIWE_SIGNING_KEY_1`, `SIWE_SIGNING_KEY_2`, … | yes | — | PEM RSA private keys, in order. `_1` is the active signer. |
| `CHAIN_ID` | no | `137` | Chain the sign-in is bound to (in the SIWE message). |
Expand Down Expand Up @@ -291,7 +291,7 @@ ops listeners are shared with the sign-in surface (`HTTP_ADDRESS`, `OPS_ADDRESS`

| Variable | Required | Default | Notes |
|----------|----------|---------|-------|
| `PERMISSIONS_ISSUER` | yes | — | `iss` on minted tokens, e.g. `https://auth-roles-rights.dimo.zone`. |
| `PERMISSIONS_ISSUER` | yes | — | `iss` on minted tokens, e.g. `https://dauth.dimo.zone/permissions`. |
| `BLOCKCHAIN_NODE_URL` | yes | — | Ethereum RPC for SACD/contract reads. |
| `IDENTITY_URL` | yes | — | identity-api GraphQL endpoint (dev-license + SACD lookups). |
| `IPFS_BASE_URL` | yes | — | IPFS gateway for template/permission documents. |
Expand Down
4 changes: 2 additions & 2 deletions charts/dauth/values-prod.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ env:
OPS_ADDRESS: "0.0.0.0:8081"
PUBLIC_BASE_URL: https://dauth.dimo.zone
# --- sign-in surface (/siwe) ---
SIWE_ISSUER: https://auth.dimo.zone
SIWE_ISSUER: https://dauth.dimo.zone/siwe
JWT_AUDIENCE: dimo
SIWE_STATEMENT: "Sign in to DIMO."
CHAIN_ID: "137"
Expand All @@ -15,7 +15,7 @@ env:
RATE_LIMIT_RPS: "50"
RATE_LIMIT_BURST: "100"
# --- token-exchange surface (/permissions) ---
PERMISSIONS_ISSUER: https://auth-roles-rights.dimo.zone
PERMISSIONS_ISSUER: https://dauth.dimo.zone/permissions
TOKEN_EXPIRATION: 10m
GRPC_PORT: "8086"
ENABLE_PPROF: "false"
Expand Down
4 changes: 2 additions & 2 deletions charts/dauth/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ env:
HTTP_ADDRESS: 0.0.0.0:8080
OPS_ADDRESS: 0.0.0.0:8081
PUBLIC_BASE_URL: https://dauth.dev.dimo.zone
SIWE_ISSUER: https://auth.dev.dimo.zone
SIWE_ISSUER: https://dauth.dev.dimo.zone/siwe
JWT_AUDIENCE: dimo
SIWE_STATEMENT: Sign in to DIMO.
CHAIN_ID: '80002'
Expand All @@ -36,7 +36,7 @@ env:
ALLOWABLE_TIME_SKEW: 5m
RATE_LIMIT_RPS: '20'
RATE_LIMIT_BURST: '40'
PERMISSIONS_ISSUER: https://auth-roles-rights.dev.dimo.zone
PERMISSIONS_ISSUER: https://dauth.dev.dimo.zone/permissions
TOKEN_EXPIRATION: 10m
GRPC_PORT: '8086'
ENABLE_PPROF: 'false'
Expand Down
11 changes: 6 additions & 5 deletions internal/config/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -32,13 +32,14 @@ type Settings struct {

// PublicBaseURL is the externally reachable origin of the merged service
// (e.g. https://dauth.dimo.zone). It is the base for each surface's published
// jwks_uri — https://dauth.dimo.zone/siwe/keys and /permissions/keys — which
// is decoupled from the iss claims (those stay auth.dimo.zone and
// auth-roles-rights.dimo.zone). Required.
// jwks_uri — https://dauth.dimo.zone/siwe/keys and /permissions/keys — and,
// by convention, for the iss claims (https://dauth.dimo.zone/siwe and
// /permissions), so each surface's discovery document is self-consistent.
// Required.
PublicBaseURL string

// Token / issuer identity for the sign-in (/siwe) surface.
Issuer string // SIWE_ISSUER (e.g. https://auth.dimo.zone) — required
Issuer string // SIWE_ISSUER (e.g. https://dauth.dimo.zone/siwe) — required
Domain string // SIWE_DOMAIN host; defaults to the PublicBaseURL host
Audience []string // JWT_AUDIENCE (comma-separated) — required
Statement string // SIWE_STATEMENT shown in the wallet prompt
Expand Down Expand Up @@ -90,7 +91,7 @@ func Load() (Settings, error) {
}

if s.Issuer == "" {
return s, errors.New("SIWE_ISSUER is required (e.g. https://auth.dimo.zone)")
return s, errors.New("SIWE_ISSUER is required (e.g. https://dauth.dimo.zone/siwe)")
}
issuerURL, err := url.Parse(s.Issuer)
if err != nil || issuerURL.Scheme == "" || issuerURL.Host == "" {
Expand Down
2 changes: 1 addition & 1 deletion internal/docs/dauth_docs.go
Original file line number Diff line number Diff line change
Expand Up @@ -147,7 +147,7 @@ const docTemplatedauth = `{
"properties": {
"challenge": {
"type": "string",
"example": "auth.dimo.zone wants you to sign in with your Ethereum account:..."
"example": "dauth.dimo.zone wants you to sign in with your Ethereum account:..."
},
"expires_at": {
"type": "string",
Expand Down
2 changes: 1 addition & 1 deletion internal/docs/dauth_swagger.json
Original file line number Diff line number Diff line change
Expand Up @@ -140,7 +140,7 @@
"properties": {
"challenge": {
"type": "string",
"example": "auth.dimo.zone wants you to sign in with your Ethereum account:..."
"example": "dauth.dimo.zone wants you to sign in with your Ethereum account:..."
},
"expires_at": {
"type": "string",
Expand Down
2 changes: 1 addition & 1 deletion internal/docs/dauth_swagger.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ definitions:
server.challengeResponse:
properties:
challenge:
example: auth.dimo.zone wants you to sign in with your Ethereum account:...
example: dauth.dimo.zone wants you to sign in with your Ethereum account:...
type: string
expires_at:
example: "2026-06-14T17:25:00Z"
Expand Down
2 changes: 1 addition & 1 deletion internal/server/handlers.go
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ type challengeRequest struct {
}

type challengeResponse struct {
Challenge string `json:"challenge" example:"auth.dimo.zone wants you to sign in with your Ethereum account:..."`
Challenge string `json:"challenge" example:"dauth.dimo.zone wants you to sign in with your Ethereum account:..."`
Nonce string `json:"nonce" example:"a1b2c3..."`
ExpiresAt string `json:"expires_at" example:"2026-06-14T17:25:00Z"`
}
Expand Down
2 changes: 1 addition & 1 deletion internal/tokenexchange/config/settings.go
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ type Settings struct {
EnablePprof bool

// Issuer is the iss claim stamped on minted permission tokens (e.g.
// https://auth-roles-rights.dimo.zone). It is namespaced (PERMISSIONS_ISSUER)
// https://dauth.dimo.zone/permissions). It is namespaced (PERMISSIONS_ISSUER)
// because the merged binary's sign-in surface has its own distinct issuer.
// TokenExpiration is the permission-token lifetime.
Issuer string
Expand Down
Loading