LogicSRC standards surface
++ OAuth 2.1 with a grant you can carry. One account at a hub, every app keeps its own + users and links them once, and what you gave and what you paid for is yours across all + of them. +
+
+ Every app has a permissions model and a billing model, and no two agree. In one
+ company's fifteen repositories we counted twelve permission vocabularies and not one
+ shared validator. An agent working across them holds twelve credentials and understands
+ none. A person who pays for a product pays again next door, because the subscription
+ lives in the seller's table and nowhere else. OpenAccess puts the pieces that already
+ exist, OAuth 2.1, /.well-known/ and webhooks, together so the
+ grant and the entitlement belong to the person, and travel.
+
+ Status: 0.1. A hub is running at{" "} + openaccess.logicsrc.com: sign in, see every + app you linked, revoke a grant, hand a narrower one to an agent, pay or cancel a + subscription from one page. Reference implementation at{" "} + github.com/logicsrc/openaccess: a hub + on Node 24 with one SQLite file, and a client and CLI. +
+
+ Served at /.well-known/openaccess.json. The scopes an app
+ understands, the products it sells, the products it honours, and the key it signs with.
+
{DESCRIPTOR}
+
+ scopes is the registry: a hub refuses any scope not named here,
+ by name, and never narrows silently. offers carry the pay,
+ cancel, manage, upgrade and promote links, with {"{principal}"}{" "}
+ filled in so a sale or a referral is attributed. honours is the
+ app's promise to treat an entitlement as paid whoever sold it.{" "}
+ jwks is the app's credential; there is no shared secret to
+ leak. operator is the person answerable, as an{" "}
+ OpenProfile.md.
+
Three are OAuth as it stands. The fourth is the one OAuth lacks.
+| Flow | +How | +Then | +
|---|---|---|
| + {flow} + | +{how} | +{then} | +
A JWT signed by the hub with Ed25519, verified offline against its JWKS.
+{TOKEN}
+
+ grant is the handle, parent the path
+ back to the person, limits the app's to enforce and the
+ hub's to keep no larger than the parent's.{" "}
+ entitlements is a snapshot of the honoured products the
+ principal holds. Webhooks carry{" "}
+ X-OpenAccess-Signature: ed25519=<signature of the raw body>,
+ verified against the same key that signs tokens.
+
{CLI}
+ | + {what} + | +{why} | +
npx @logicsrc/openaccess
+