Standard OAuth authentication powered by on-chain identity and permissions.
Use wallets as identities.
Use on-chain state as access control.


Works with any OAuth2 or OIDC library












[ 01 / 05 ]
The Problem
Bittensor identity has no standard authentication layer
Custom auth gets rebuilt for every subnet
OAuth doesn't understand miners or stake
Off-the-shelf tools can't authenticate
Can't login with a browser wallet
[ 02 / 05 ]
Solution
taostats auth
Taostats Auth Gateway connects Bittensor identity to the existing OAuth ecosystem.


[ 03 / 05 ]
Process
Taostats Auth Gateway connects Bittensor identity to the existing OAuth ecosystem.
On-chain scopes are re-verified at every token refresh. If a miner deregisters, their access lapses automatically at the next epoch. No manual revocation.


[ 04 / 05 ]
Scopes
Scope
Verifies
subnet:1:miner
Registered miner
subnet:1:validator
Validator
subnet:18:owner
Subnet owner
subnet:1:holder:100
Alpha holder
tao:holder:50
TAO holder
delegate:{hotkey}
Delegator relationship
staker:1000
Network stake
Headless Miner Auth
CLI authentication using Device Code Flow (RFC 8628)
Validator Dashboards
Gate access to subnet validators. Access auto-revokes when deregistered.
Token Gated Content
Different content at different holder thresholds.
Subnet Owner Portals
Verify subnet ownership automatically, no allowlist required.
Authorization Code + PKCE
Standard web application login
Device Code Flow
CLI and headless authentication
OpenID Connect
Full OIDC compatibility
[1]
Standard OAuth2/OIDC — no custom SDK.
[2]
JWKS endpoint for resource server validation.
[3]
Token claims include hotkey, coldkey, scope, sub.
[ 05 / 05 ]
Trust & Security
This is a centralised layer on a decentralised system. Open source and self-hostable.
Signing
Signing on Taostats infrastructure
Re-verified
Re-verified at every token refresh
Epoch-aligned
Epoch-aligned expiry
PKCE Flow
PKCE required for public clients
No Database
Chain is truth, no role database
Self Hostable
Open source, self-hostable