# Flowsta Developer Documentation - docs.flowsta.com > Technical documentation for Flowsta: sovereign login (OAuth 2.0 + PKCE and the Flowsta Vault), Sign It file signing, webhooks, and the Vault's local IPC for Holochain and desktop apps. Built on Holochain. ## What Flowsta is A Flowsta identity lives on the user's own device: a 24-word recovery phrase derives Ed25519 keys, and the Flowsta Vault desktop app holds them with a personal Holochain node. There is no password on any server. A sign-in or a signature is a challenge the Vault signs and the user approves. Three building blocks for developers: 1. Sovereign login - OAuth 2.0 + PKCE for web apps; local Vault IPC for desktop and Holochain apps. 2. Sign It - cryptographic file signing and verification, approved per signature in the user's Vault. 3. Webhooks - HMAC-signed events from your app's users. ## Rules that shape every integration - The Vault decides who is signing in. A remembered web session is reused only when it belongs to the identity the Vault holds now. - Key users by `sub` (OAuth) or the agent public key / DID (Vault). A re-authorization can return a different person. - An email is shared only when the user allows it in their Vault; design for no email. - A Holochain app agent links to ONE Flowsta identity. Many app agents may link to one identity; one agent never links to two. - A web session belongs to the identity that signed in. Switching identity in the Vault does not end or move it. ## Pages ### Start - [Start here](https://docs.flowsta.com/getting-started/): What are you building? A web app, a Holochain app, or something that signs files - pick your path. How a Flowsta identity works, what every path shares, and where to register your app. - [Quick Start Guide](https://docs.flowsta.com/getting-started/quickstart): Get started with Flowsta Auth in 5 minutes. Choose your integration path - OAuth SSO for web apps or identity linking for desktop Holochain apps. - [Register Your App](https://docs.flowsta.com/getting-started/register-app): Register your application on the Flowsta Developer Dashboard. Get your client ID for OAuth web apps or Holochain desktop apps. ### Understand - [Flowsta Vault](https://docs.flowsta.com/vault/): Flowsta Vault is the home of every Flowsta identity - the keys, the private data and every approval live on the user's own device. What it is, what it holds, and what it means for web, Holochain and desktop apps. - [Security & Privacy](https://docs.flowsta.com/security/): Security architecture of Flowsta Auth. Device-held keys, zero-knowledge privacy, passwordless sign-in, PKCE authentication, and user-owned data export. - [Zero-Knowledge Architecture](https://docs.flowsta.com/security/zero-knowledge): How Flowsta Auth achieves zero-knowledge privacy. Keys and private data live on your device in Flowsta Vault - Flowsta holds only an email hash and cannot decrypt anything. - [What the Vault Sends Home](https://docs.flowsta.com/security/usage-data): A complete, field-by-field account of everything Flowsta Vault sends to Flowsta in the background - what it contains, why it exists, and who can see what. - [Data Portability](https://docs.flowsta.com/security/data-portability): How users export and restore their data from Flowsta Vault. Structured JSON export, device keys, private records, app backups, and CAL compliance. - [Sessions & Tokens](https://docs.flowsta.com/security/sessions): How Flowsta sessions work for developers. OAuth access and refresh token lifetimes, the flowsta_session SSO cookie, stateless JWTs, sign-out, and how a session relates to the Vault identity that signed in. - [Holochain Architecture](https://docs.flowsta.com/holochain/architecture): How Flowsta uses Holochain for decentralized identity. Three-DNA architecture, global and community-run DHT nodes, and local conductors in Flowsta Vault. - [Identity & DIDs](https://docs.flowsta.com/holochain/identity): W3C Decentralized Identifiers in Flowsta Auth. Ed25519 keypairs, DID generation, and self-sovereign identity. ### Web apps - [Sign in with Flowsta](https://docs.flowsta.com/auth/): Add Sign in with Flowsta using OAuth 2.0 + PKCE. Users approve every sign-in with their Flowsta Vault - keys only they hold, no password to phish, no one in between. - [Quick Start](https://docs.flowsta.com/auth/quickstart) - [Login Button Widget](https://docs.flowsta.com/auth/button-widget) - [Vanilla JS](https://docs.flowsta.com/auth/vanilla-js) - [Security](https://docs.flowsta.com/auth/security) - [OAuth API Reference](https://docs.flowsta.com/auth/api-reference) ### Webhooks - [Overview](https://docs.flowsta.com/webhooks/) - [Event Types](https://docs.flowsta.com/webhooks/events) - [Verification](https://docs.flowsta.com/webhooks/verification) - [Delivery & Failures](https://docs.flowsta.com/webhooks/delivery) ### Packages - [@flowsta/auth SDK](https://docs.flowsta.com/sdk/auth): Complete reference for @flowsta/auth. OAuth 2.0 + PKCE authentication, Vault-first document signing, and React bindings - no one in between. - [@flowsta/login-button](https://docs.flowsta.com/sdk/login-button): Pre-built 'Sign in with Flowsta' button components for React, Vue, Qwik, and vanilla JavaScript. PKCE and the OAuth redirect built in. - [Sign in with Flowsta Buttons](https://docs.flowsta.com/sdk/buttons): Official 'Sign in with Flowsta' button assets - SVG and PNG downloads in six variants, with size and usage guidelines. ### Holochain apps - [Holochain apps](https://docs.flowsta.com/holochain/): Your options as a Holochain developer - sign-in only, link your app's agent to a Flowsta identity, or a desktop app without Holochain - and what a linked app gets - profile, encrypted backups, reinstall recovery, CAL export, Sign It. - [Building Holochain Apps with Flowsta](https://docs.flowsta.com/holochain/build): Integrate Flowsta identity linking into your Holochain application. Add the agent-linking zomes, install the SDK, and let users prove their Flowsta identity on your DHT. - [Agent Linking](https://docs.flowsta.com/holochain/agent-linking): Link your Holochain app's agent key with the user's Flowsta Vault identity. Cryptographic attestations on your own DHT, verifiable by anyone with no one in between. - [Identity Switching](https://docs.flowsta.com/vault/identity-switching): From Vault 1.5.0 one Flowsta Vault holds several identities on one computer. What your Holochain or desktop app observes when the person switches, the rule every linked app must follow, and the two ways to build for it. - [@flowsta/holochain SDK](https://docs.flowsta.com/sdk/holochain): SDK for integrating Holochain apps with Flowsta Vault. Agent linking, Vault sign-in, document signing, encrypted auto-backups, and restore. - [Desktop App Authentication](https://docs.flowsta.com/desktop/): Authenticate desktop applications through Flowsta Vault. Sign-in, identity, and agent linking over local IPC - your app never handles credentials. ### Reference - [IPC Endpoints](https://docs.flowsta.com/vault/ipc-reference): Reference for Flowsta Vault's local IPC API. Status, agent linking, authentication, backups, document signing, signature management, async jobs, flowsta:// links, and every error code. ### Sign It - [Sign It - Document Signing & Verification](https://docs.flowsta.com/sign-it/): Cryptographic document signing from your own Flowsta Vault. Your keys never leave your device, you approve every signature, and anyone can verify - no one in between. - [Sign It Quickstart](https://docs.flowsta.com/sign-it/quickstart): Sign your first file from your Flowsta Vault, verify it on the web, and request signatures from your own app. - [Content Rights Manifest](https://docs.flowsta.com/sign-it/content-rights): Declare license, commercial availability, AI training policy, and contact preferences with cryptographic proof - signed in your own Vault, checkable by any machine. - [Sign It Badge & Widget](https://docs.flowsta.com/sign-it/badge): Embed a verification badge or card on any website with two lines of HTML. ### For Developers - [Sign It Developer Guide](https://docs.flowsta.com/sign-it/developer-guide): Add Vault-based document signing to your web or desktop app - user-approved signatures, publishing from a linked app, sponsored signing pools, and quota management. - [Sign It Verification API](https://docs.flowsta.com/sign-it/verification-api): API reference for programmatic signature verification, fuzzy matching, content rights lookup, and signing quotas. - [Sign It SDK Reference](https://docs.flowsta.com/sign-it/sdk-reference): Complete SDK reference for Sign It - Vault-based signing with per-signature user approval, publishing from linked apps, verification, and content rights. ### Reference - [Reference](https://docs.flowsta.com/reference/): Every reference surface in one place - the SDK packages, the REST and OAuth APIs, the Vault's local bridge, and the machine-readable index for AI assistants. - [SDK Documentation](https://docs.flowsta.com/sdk/): The three Flowsta SDK packages - @flowsta/auth for OAuth sign-in and web signing, @flowsta/login-button for ready-made buttons, @flowsta/holochain for Vault-linked Holochain apps. ### APIs - [API Reference](https://docs.flowsta.com/api-reference/): Overview of the Flowsta Auth API surface. Base URL, versioning, authentication header, error envelopes, rate limits, and links to the OAuth, Vault IPC, Sign It and webhook references. ### Changelog - [Changelog](https://docs.flowsta.com/changelog): Version history for Flowsta Auth. See what's new in each release. ## npm packages (published versions) - @flowsta/auth@2.6.1 - @flowsta/login-button@0.1.6 - @flowsta/holochain@3.6.1 ## Public endpoints (no auth) - Sign It verify: GET https://auth-api.flowsta.com/api/v1/sign-it/verify?hash= - Content rights for AI pipelines: GET https://auth-api.flowsta.com/api/v1/sign-it/content-rights?hash= - Sign It badge: GET https://auth-api.flowsta.com/api/v1/sign-it/badge?hash=&format=svg|json ## Links - Developer dashboard: https://dev.flowsta.com - Full text of every page: https://docs.flowsta.com/llms-full.txt - Source: https://github.com/WeAreFlowsta