Reference
Authentication
Seven Pro wallet sign-in methods on /authpi, plus Connect with OpenPay (OAuth) for third-party apps.
Sign-in UI:
https://openpaypro.space/authpi · Deep narrative + env samples: /docs/openpay#auth · Raw: /api/public/docs/openpay-auth01
Seven Pro sign-in methods
| Method | Type | Backend |
|---|---|---|
| OpenPay | OAuth 2.0 | /api/public/openpay-auth |
| Telegram | Login Widget · OIDC + PKCE | /api/public/telegram-auth |
| Solana | Sign In With Solana | /api/public/solana-auth |
| Pi Network | Pi SDK / Pi OAuth | /api/public/pi-auth |
| Phantom | Phantom Connect | /auth/callback |
| WalletConnect | EVM SIWE | /api/public/walletconnect-auth |
| MetaMask | Embedded / Web3Auth | /api/public/web3auth-auth |
All successful flows end in a Supabase session and redirect to /dashboard (or your redirectTo).
02
Connect with OpenPay (partners)
Third-party apps do not embed every wallet method — they use Connect with OpenPay so users link an openpy.space account.
- Register an app at Partner portal; allowlist exact redirect URIs.
- Send users to
https://openpy.space/connect?client_id=...&redirect_uri=...&scope=profile%20balance&state=... - Exchange
codeforopa_live_...on your server (see /docs/api#oauth).
import { startOpenPaySignIn } from "@/lib/openpay-auth"
await startOpenPaySignIn({ redirectTo: "/dashboard" })03
Shared server env
OPENPAY_AUTH_PASSWORD_SECRET="long-random-string"
SUPABASE_URL="https://YOUR_PROJECT.supabase.co"
SUPABASE_PUBLISHABLE_KEY="eyJ..."
SUPABASE_SERVICE_ROLE_KEY="eyJ..." # server only — never VITE_
OPENPAY_OAUTH_AUTHORIZE_URL="https://openpy.space/connect"
OPENPAY_OAUTH_CLIENT_ID="your-client-uuid"
OPENPAY_PARTNER_API_KEY="opk_live_..."Method-specific secrets and Pi / Telegram / Web3Auth knobs are documented in docs/OPENPAY_PRO_AUTH.md.
04
Security rules
- Keep
opk_live_and service-role keys on the server only. - Validate OAuth
state/ PKCE where used. - Register exact redirect URIs — no open redirects.
- Partners accepting payments: poll charges — see /docs/errors.