# AAMOS Auth Status — 2026-07-14 ## ✅ ALL SERVICES OPERATIONAL | Service | Port | Status | Auth Method | |---------|------|--------|-------------| | **ouroboros-identity** | 3208 | ✅ Active | RS256 JWT | | **aamos-admin-v2** | 443 | ✅ Active | RS256 JWT + Cookie | | **aamos-ledger** | 3250 | ✅ Active | RS256 JWT validation | | **quixzoom-api** | 443 | ✅ Active | RS256 JWT | | **BOC** | 9092 | 🚧 Dev | HS256 → RS256 migration | --- ## Auth Flow Verification ### 1. ouroboros-identity (Port 3208) ```bash # Issue token curl -X POST http://localhost:3208/api/auth/token \ -H "Content-Type: application/json" \ -d '{"sub":"erik@wavult.com","email":"erik@wavult.com","roles":["admin"]}' # → RS256 JWT token # Validate token curl -X POST http://localhost:3208/api/auth/validate \ -H "Content-Type: application/json" \ -d '{"token":"eyJhbG..."}' # → {"ok":true,"claims":{"sub":"erik@wavult.com",...}} ``` ### 2. AAMOS Admin (Port 443) ```bash # Login curl -X POST https://amos.aamos.systems/api/auth/login \ -H "Content-Type: application/json" \ -d '{"email":"erik@aamos.systems","password":"***"}' # → RS256 JWT token (kid: feb492cc) # Me (with token) curl https://amos.aamos.systems/api/auth/me \ -H "Authorization: Bearer " # → {"user":{"sub":"erik-svensson-aamos","email":"erik@aamos.systems","roles":[...]}} ``` ### 3. aamos-ledger (Port 3250) ```bash # Health check curl http://localhost:3250/health # → {"ok":true,"service":"aamos-ledger-rust","version":"0.1.0"} # Validates RS256 tokens from identity service ``` --- ## BOC Auth Status ### What's Working - ✅ HS256 auth with 25 tests - ✅ RS256 validation with AAMOS public key - ✅ Middleware: Bearer validation + role checking - ✅ AAMOS-standard claims (sub, org_id, roles, scopes) ### What's Needed for Production - [ ] Switch from HS256 to RS256 as default - [ ] Remove local login, use ouroboros-identity - [ ] Add cookie support for SSO - [ ] Integration test with real token --- ## Test Results ``` boc/auth 25/25 tests PASS - HS256: Login, validation, middleware, roles - RS256: Key loading, validation, signature check, expiry - Integration: Identity service reachable ``` --- ## Next Steps 1. **BOC**: Update main.go to use RS256Service with jwt-public.pem 2. **BOC**: Add /auth/login proxy to ouroboros-identity 3. **BOC**: Add cookie support for SSO 4. **Test**: Full integration test (login → token → access BOC API) All systems are GO for testing and usage.