Sign in with Elixir
Elixir's own apps sign you in with your Elixir account: one consent page, and one grant you can see and end in the console. Other apps can ask too, for less.
Elixir is the account for the whole family. Elixir Clan and Elixir Drop have no sign-up of their own: they send you to Elixir, you say yes once, and they know who you are and which players are yours. Under the hood it is OAuth 2.1, the same sign-in an MCP client uses to connect.
The apps that use it
| App | Where | Asks for |
|---|---|---|
| Elixir Clan | elixir.poapkings.com/clan | cr:read and clans:attest |
| Elixir Drop | drop.poapkings.com | cr:read, recordings:write and account:email |
Both are family apps: clients Elixir provisioned itself, each with a
secret, with every return address on a family origin. A family app
reads the JSON API as you without an hourly limit,
and only a family app can be given account:email or clans:attest.
They learn who you are, and the players you track, from
GET /api/v1/me.
What you see
Signed in at elixir.poapkings.com already, the page reads Connect and the app's name, says which address you are signed in as, and has one Authorize button, with a link to sign in with a code instead when the browser is not yours. Not signed in, you enter your email and then the six-digit code it sends (15 minutes, five tries); approving that way signs the browser in to Elixir too.
Above the button, the page says who is asking in words the app did not
choose. A family app "is one of Elixir's own apps", and the page names
the address approving sends you back to. Any other app "named itself;
Elixir has not checked it", and the page asks you to continue only if
you started the connection and trust that address. Then come the
capabilities the app asked for. Other ordinary capabilities are offered
as boxes, unticked; account:email and clans:attest are never offered
unasked.
Not asked twice
Elixir Clan lives on Elixir's own address, so while you hold a live grant to it that covers what it asks for, signing in to Clan goes straight through with no page. Elixir Drop, on its own address, shows the page each time. Revoking the grant, or narrowing it, brings the page back.
Ending a grant
Console ▸ Connections ▸ Clients lists every app connected to your account; Disconnect ends one at once, and its capabilities can be narrowed there. Signing out of Elixir Clan ends its grant too. A grant lasts 90 days at most; within it, the app holds an access token for an hour at a time and renews it with a refresh token that changes on every use. A refresh token used twice ends the whole grant.
For developers
Any app can register and ask a person for a grant, with no key from anyone: registration is open (dynamic client registration), the client is public, and PKCE with S256 is required. A registration is refused when its name begins with Elixir's or POAP KINGS' name, or when a return address is on a family origin. What an outside app can get:
- a grant for the JSON API (
resourcehttps://elixir.poapkings.com/api/v1) or for the person's MCP door (/mcp), never both on one token: a token for one door is refused at the other; - the ordinary capabilities below, starting from
cr:read, which every request includes; - JSON API calls up to 600 an hour for each person, shared by every outside app acting for them.
It never gets the person's email address or clans:attest, and there
is no OpenID Connect: no ID token. Who the person is comes from
GET /api/v1/me, their principal and the players they track.
| Scope | On the consent page | Who can ask |
|---|---|---|
cr:read |
Read recorded game data | any app; always included |
recordings:write |
Change what you track | any app |
collections:write |
Edit collections | any app |
account:write |
Update account preferences | any app |
feedback:write |
Send feedback | any app |
account:email |
Know your email address | family apps only |
clans:attest |
Record what you do in your clan | family apps only |
The endpoints are /.well-known/oauth-authorization-server,
/.well-known/oauth-protected-resource, /oauth/register,
/oauth/authorize, /oauth/token, /oauth/revoke and, for a family
app holding account:email, /oauth/userinfo. Every parameter, error
and token lifetime is on Protocol: OAuth 2.1.