Summary
After the user is already logged in on the mobile app, allow them to scan a QR code shown on desktop and one-tap approve so the desktop (WebUI / minibot desktop) gets a session — without re-entering email OTP / OAuth on the computer.
This is not:
- WeChat / phone IdP login
- IM channel QR (Feishu / Weixin pairing)
- Expo Go Metro QR
Priority
P2 / deferred. Desktop already has browser OAuth + handoff. RN still has open P0/P1 work; this is a convenience path and should wait until mobile login + Gateway chat are stable.
Proposed shape
| Layer |
Role |
| mini-auth |
Own the challenge / approve / token issuance (prefer extending existing Device Flow) |
| minibot Desktop / WebUI |
Show QR, poll until ready, materialize local session (reuse handoff pattern) |
| minibot-react-native |
Scan (or open deep link) → if already logged in, confirm → call approve API |
Happy path:
- Desktop: “用手机扫码登录” → start device / login challenge
- QR encodes
verification_uri_complete (or app deep link)
- RN: scan → one-tap approve with existing session
- Desktop: poll → install session (e.g. existing
/auth/desktop/session-style handoff)
Avoid a minibot-only private “mobile token → desktop cookie” protocol long-term; identity confirmation belongs at the IdP.
RN scope (this repo)
Related
- mini-auth: Device Authorization Grant already exists for CLI; needs mobile-friendly approve UX
- minibot: desktop browser login +
/auth/desktop/handoff already ships; QR path would be additive
- Cross-device login discussion: phone-as-authenticator for desktop (Codex / Discord style)
Out of scope (for now)
- Using RN to log in a brand-new account via QR alone
- Replacing primary email OTP / Google / GitHub on RN
Summary
After the user is already logged in on the mobile app, allow them to scan a QR code shown on desktop and one-tap approve so the desktop (WebUI / minibot desktop) gets a session — without re-entering email OTP / OAuth on the computer.
This is not:
Priority
P2 / deferred. Desktop already has browser OAuth + handoff. RN still has open P0/P1 work; this is a convenience path and should wait until mobile login + Gateway chat are stable.
Proposed shape
Happy path:
verification_uri_complete(or app deep link)/auth/desktop/session-style handoff)Avoid a minibot-only private “mobile token → desktop cookie” protocol long-term; identity confirmation belongs at the IdP.
RN scope (this repo)
Related
/auth/desktop/handoffalready ships; QR path would be additiveOut of scope (for now)