One Login Kit
Download the branded migration guide and the paste-ready brief, then distribute them to every Cargo spoke.
Cargo Ecosystem // One Login
Spoke Migration Kitcargo.ac owns identity · credentials live ONLY on one.cargo.ac · every spoke registers a Custom OIDC Provider with Auto-discovery OFF (issuer copied from live discovery, endpoints on auth.cargo.ac) and shows one "Continue with Cargo Account" button · tokens trusted via JWKS · one global logout.
These documents are guidance, not gospel. Tell each spoke to confirm every endpoint, claim and scope against live OIDC discovery and JWKS before using it — and to stop and ask if anything conflicts with its real stack.
Markdown · share with Cursor, one.cargo.ac AND the hub
CargoApp Master Federation Doc (3 teams)
ONE shared brief for all three parties connecting CargoApp to Cargo Account. Part 0 explains the cast of characters and who shares which Supabase backend (hub + admin.cargo.ac + one.cargo.ac = one project; CargoApp/api.cargo.app = a separate one), and why auth.cargo.ac is a backend endpoint while the issuer is the raw backend host. Part 1 is the full Flutter playbook for Cursor (incl. how mobile actually works — the in-app browser renders one.cargo.ac, only the final redirect is a deep link). Part 2 is the one.cargo.ac action list. Part 3 is the hub admin's steps. Part 4 is a shared flow diagram + glossary.
PDF · 9 pages · branded · print-ready
One Login — Spoke Migration Guide
The full, CargoWorks-branded manual: what changes, ecosystem endpoints, identity claims, delete-vs-add checklist, the masked-hybrid Custom OIDC model (Auto-discovery OFF, issuer copied from live discovery), step-by-step backend + TanStack migration, DB/RLS rules, acceptance checklist and roll-out order.
Markdown · drop into each web spoke's platform chat
Paste-Ready Spoke Brief (web)
A hardened prompt that instructs each web spoke's AI exactly what to remove, add and configure — and to verify every value against live discovery instead of copying blindly.
Markdown · CargoApp-only excerpt · superseded by the Master Doc
CargoApp Playbook (Flutter native) — excerpt
The CargoApp-only Flutter brief (supabase_flutter + a Custom OIDC Provider on api.cargo.app, PKCE public client with no secret on device, deep-link return, iOS/Android setup). Kept for continuity — prefer the Master Federation Doc above, which contains this content as Part 1 plus the one.cargo.ac and hub sections so all three teams share one document.
Distribute to: CargoWorks AI · IO · Directory · Cargo E-Mail · Network HUB · Websites.
