Reference

Authentication

Seven Pro wallet sign-in methods on /authpi, plus Connect with OpenPay (OAuth) for third-party apps.

Sign-in UI: https://openpaypro.space/authpi · Deep narrative + env samples: /docs/openpay#auth · Raw: /api/public/docs/openpay-auth

01

Seven Pro sign-in methods

MethodTypeBackend
OpenPayOAuth 2.0/api/public/openpay-auth
TelegramLogin Widget · OIDC + PKCE/api/public/telegram-auth
SolanaSign In With Solana/api/public/solana-auth
Pi NetworkPi SDK / Pi OAuth/api/public/pi-auth
PhantomPhantom Connect/auth/callback
WalletConnectEVM SIWE/api/public/walletconnect-auth
MetaMaskEmbedded / Web3Auth/api/public/web3auth-auth

All successful flows end in a Supabase session and redirect to /dashboard (or your redirectTo).

02

Connect with OpenPay (partners)

Third-party apps do not embed every wallet method — they use Connect with OpenPay so users link an openpy.space account.

  1. Register an app at Partner portal; allowlist exact redirect URIs.
  2. Send users to https://openpy.space/connect?client_id=...&redirect_uri=...&scope=profile%20balance&state=...
  3. Exchange code for opa_live_... on your server (see /docs/api#oauth).
import { startOpenPaySignIn } from "@/lib/openpay-auth"
await startOpenPaySignIn({ redirectTo: "/dashboard" })

03

Shared server env

OPENPAY_AUTH_PASSWORD_SECRET="long-random-string"
SUPABASE_URL="https://YOUR_PROJECT.supabase.co"
SUPABASE_PUBLISHABLE_KEY="eyJ..."
SUPABASE_SERVICE_ROLE_KEY="eyJ..."   # server only — never VITE_

OPENPAY_OAUTH_AUTHORIZE_URL="https://openpy.space/connect"
OPENPAY_OAUTH_CLIENT_ID="your-client-uuid"
OPENPAY_PARTNER_API_KEY="opk_live_..."

Method-specific secrets and Pi / Telegram / Web3Auth knobs are documented in docs/OPENPAY_PRO_AUTH.md.

04

Security rules

  • Keep opk_live_ and service-role keys on the server only.
  • Validate OAuth state / PKCE where used.
  • Register exact redirect URIs — no open redirects.
  • Partners accepting payments: poll charges — see /docs/errors.