Skip to content

Support customer-managed Cloudflare OAuth - #54

Draft
olegberman wants to merge 1 commit into
mainfrom
agent/customer-managed-oauth
Draft

Support customer-managed Cloudflare OAuth#54
olegberman wants to merge 1 commit into
mainfrom
agent/customer-managed-oauth

Conversation

@olegberman

Copy link
Copy Markdown
Contributor

Summary

  • keep the official HQBase OAuth relay as the default
  • add a customer-managed private OAuth client mode using direct Cloudflare authorization with PKCE
  • add installer and operator configuration without API tokens or client secrets
  • exercise direct OAuth in staging and disable Worker invocation logs

Validation

  • CI=true pnpm check
  • CI=true pnpm deploy:dry-run
  • git diff --check

Dependencies

Merge the contract and OAuth relay PRs first. The staging environment also needs HQBASE_E2E_OAUTH_CLIENT_ID before the staging E2E run.

@olegberman
olegberman deployed to hqbase-staging July 28, 2026 22:13 — with GitHub Actions Active
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant