Aniyori Identity at auth.aniyori.cz is the sole identity authority. Web clients use Authorization Code + PKCE S256, state and nonce; refresh tokens rotate.
Client Credentials supports operator-configured confidential machine clients linked to an ApplicationId, environment and allowed anime.read / search.read scopes. Self-service OAuth client management is not available yet.
Machine tokens have no human identity, refresh token or /me access. The API also checks that the application is active on every request. Implicit and password grants are disabled.
The first-party web/admin/developers clients are trusted applications. Third-party delegated client registration and consent UI are planned for a later phase.
curl "$ANIYORI_IDENTITY_URL/connect/token" \
-d grant_type=client_credentials \
-d client_id="$ANIYORI_CLIENT_ID" \
-d client_secret="$ANIYORI_CLIENT_SECRET" \
-d scope=anime.read