This document describes the Single Sign-On (SSO) integration between app.devcon.org and app.meerkat.events.
When a Devcon user clicks a link to Meerkat, they are transparently authenticated without a separate login. The flow is based on a one-time opaque code embedded in the redirect URL, exchanged server-to-server using a pre-shared API key. No OAuth infrastructure is required.
Key properties:
- Short-lived code (TTL 60s), single-use, 32 bytes of CSPRNG entropy