IDENTITY ONLY
scope=openidNo raw provider ID, wallet, authenticated chain data, passkey credential, public key, email, handle, name, avatar, or provider access token.
ONE LOGIN. THREE EXPLICIT IDS.
One sign-in layer for browser, CLI, and device apps. Keep continuity across your products, or give every client its own private user ID.
Email is profile data, not a key. Every token names exactly which identity contract it carries.
Provider-global and correlatable across Triad clients that receive it, without exposing the upstream ID.
Broker-global. Correlates one Triad account across clients.
Stable inside one app. Different client, different identifier.
A client chooses its request. Triad shows the complete list before approval, and shares nothing beyond it.
scope=openidNo raw provider ID, wallet, authenticated chain data, passkey credential, public key, email, handle, name, avatar, or provider access token.
OPTIONAL CLAIM SCOPES
Triad derives the client from the callback origin, then binds the exact URI and S256 verifier.
?client_id=issued-client-id
&redirect_uri=https://example.com/oauth/callback
&scope=openid
&resource=https://resource.example/
&code_challenge=...
&code_challenge_method=S256Show a short code on the device. The user opens Triad in a browser and approves either a Triad session or scoped OAuth tokens for a registered client.
OPEN DEVICE VERIFICATION →